Internet Information Services Other Vulnerability - CVE-2000-0025
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com .exe .sh .cgi or .dll aka the quotVirtual Directory Namingquot vulnerability.