Multiple Web Server Encoded Space (%20) Request ASP Source Disclosure

medium Nessus Plugin ID 11071

Synopsis

The remote web server is affected by an information disclosure vulnerability.

Description

It appears possible to get the source code of the remote ASP scripts by appending a '%20' to the request.

ASP source code usually contains sensitive information such as logins and passwords.

This has been reported in Simple HTTPD (shttpd), Mono XSP for ASP.NET and vWebServer. This type of request may affect other web servers as well.

Solution

There is no known solution at this time.

See Also

https://seclists.org/bugtraq/2006/Dec/326

https://seclists.org/bugtraq/2007/Jun/260

Plugin Details

Severity: Medium

ID: 11071

File Name: asp_source_space.nasl

Version: 1.39

Type: remote

Family: Web Servers

Published: 8/14/2002

Updated: 6/3/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2001-1248

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:U/RC:C

Vulnerability Information

Required KB Items: www/ASP

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Vulnerability Publication Date: 6/29/2001

Reference Information

CVE: CVE-2001-1248, CVE-2007-3407

BID: 2975

Secunia: 25809