CVE-1999-0450

Internet Information Server - Path Disclosure via Perl Script Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0450. PoCs published by Mnemonix.

AI-analyzed exploit summary This is a writeup describing an information leakage vulnerability in IIS where a GET request for a nonexistent file with an IISAPI-registered extension reveals the full path of the root web server directory. The example shows an error message exposing the path 'C:\InetPub\scripts\bogus.pl'.

Description

In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

Exploits (1)

exploitdb WRITEUP VERIFIED
by Mnemonix · textremotewindows
https://www.exploit-db.com/exploits/19152

This is a writeup describing an information leakage vulnerability in IIS where a GET request for a nonexistent file with an IISAPI-registered extension reveals the full path of the root web server directory. The example shows an error message exposing the path 'C:\InetPub\scripts\bogus.pl'.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Information Services (IIS)
No auth needed
Prerequisites: Access to send HTTP GET requests to the target IIS server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/194

Scores

EPSS 0.1743
EPSS Percentile 96.7%

Details

Status published
Products (4)
microsoft/internet_information_server 3.0
microsoft/internet_information_server 4.0
microsoft/internet_information_services 2.0
microsoft/internet_information_services 5.0
Published Jan 26, 1999
Tracked Since Feb 18, 2026