In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
CVSS Metrics