Show filters
46 Total Results
Displaying 41-46 of 46
Sort by:
Attacker Value
Unknown

CVE-2000-0304

Disclosure Date: May 10, 2000 (last updated February 22, 2025)
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.
0
Attacker Value
Unknown

CVE-2000-0413

Disclosure Date: May 06, 2000 (last updated February 22, 2025)
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.
0
Attacker Value
Unknown

CVE-2000-0258

Disclosure Date: April 12, 2000 (last updated February 22, 2025)
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
0
Attacker Value
Unknown

CVE-2000-0246

Disclosure Date: March 30, 2000 (last updated February 22, 2025)
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
0
Attacker Value
Unknown

CVE-2000-0071

Disclosure Date: January 11, 2000 (last updated February 22, 2025)
IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.
0
Attacker Value
Unknown

CVE-1999-0450

Disclosure Date: January 26, 1999 (last updated February 22, 2025)
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
0