CVE-2000-0071

EXPLOITED

Internet Information Server 4.0 - Path Disclosure via .ida or .idq File Request

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2000-0071 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=94780058006791&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=94770020309953&w=2

Scores

EPSS 0.2651
EPSS Percentile 97.8%

Details

VulnCheck KEV 2000-01-11
Status published
Products (3)
microsoft/internet_information_server 3.0
microsoft/internet_information_server 4.0
microsoft/internet_information_services 5.0
Published Jan 11, 2000
Tracked Since Feb 18, 2026