CVE-2000-0024
Internet Information Server - URL Access Restriction Bypass via Escape Character Parsing
Title source: llmDescription
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ246401
Various Sources x_refsource_misc
http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-061
Scores
EPSS
0.1222
EPSS Percentile
95.8%
Details
Status
published
Products (3)
microsoft/internet_information_server
4.0
microsoft/site_server
3.0
microsoft/site_server_commerce
3.0
Published
Dec 21, 1999
Tracked Since
Feb 18, 2026