Description
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.
Remediation
References
Related Vulnerabilities
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-8140)
WordPress Plugin Mapwiz SQL Injection (1.0.1)
MySQL CVE-2019-2920 Vulnerability (CVE-2019-2920)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1099)
Jenkins Insufficient Verification of Data Authenticity Vulnerability (CVE-2015-7539)