{"id":"CVE-1999-0253","title":"IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a ","summary":"IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.","severity":"high","cvss":7.5,"cvssVector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","published":"1997-01-01","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-0253","references":[{"url":"http://www.securityfocus.com/bid/1814","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/1814","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.07952,"epssPercentile":0.94571,"ingestedAt":"2026-06-22T15:59:08.168Z","slug":"CVE-1999-0253","body":"## Overview\n\nIIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":41.3,"likelihood":1.6,"exploitation":0,"ransomware":0},"changes":[]}