Pietro Di Mosmanza found following.  In ASP you have some built-in
    objects,  one  of  which  is  the  Request  Object.   This  object
    retrieves the values that the client browser passed to the  server
    during a HTTP request.
        Request("variable") = value

    However, when the value exists of a percentage sign (which can  be
    followed by 1 arbitrary character), Request("variable") holds some
    kind of path which can reveil some information about the  internal
    structure of  the website.   This can  be a  problem when  such  a
    variable is printed directly into  the HTML, or when the  VBscript
    can't deal with bogus input."variable") = <bogus_string>

    On some  sites it  is possible  to see  which one  of the  virtual
    sites  on  the  same  server  it  is,  you'll  see  something like
    "˙LM/W3SVC/1/Root/test".  Look for example on Microsoft's site

    Tested with ASP version 4.02.0727, IIS 4.0, NT 4.0 sp 4.


    Nothing yet.