CVE-2000-0413

The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:frontpage:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_information_server:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:32

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2000-05/0084.html - () http://archives.neohapsis.com/archives/bugtraq/2000-05/0084.html -
References () http://www.securityfocus.com/bid/1174 - () http://www.securityfocus.com/bid/1174 -

Information

Published : 2000-05-06 04:00

Updated : 2024-11-20 23:32


NVD link : CVE-2000-0413

Mitre link : CVE-2000-0413

CVE.ORG link : CVE-2000-0413


JSON object : View

Products Affected

microsoft

  • internet_information_server
  • frontpage
  • internet_information_services