CVE-1999-0725

IIS - Info Disclosure

Title source: llm
STIX 2.1

Description

When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".

Exploits (1)

exploitdb WRITEUP VERIFIED
by Microsoft · textremotewindows
https://www.exploit-db.com/exploits/19361

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/477
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ233335
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/2302

Scores

EPSS 0.3225
EPSS Percentile 96.9%

Details

CWE
CWE-16
Status published
Products (2)
microsoft/internet_information_server 3.0 (3 CPE variants)
microsoft/internet_information_server 4.0 (3 CPE variants)
Published Aug 19, 1999
Tracked Since Feb 18, 2026