CVE-2000-0304

Microsoft Internet Information Server 4.0-5.0 - Denial of Service via Malformed .HTR Request

Title source: llm
STIX 2.1

Description

Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1191
Various Sources third-party-advisory x_refsource_iss
http://xforce.iss.net/alerts/advise52.php3

Scores

EPSS 0.2774
EPSS Percentile 97.9%

Details

Status published
Products (2)
microsoft/internet_information_server 4.0
microsoft/internet_information_services 5.0
Published May 10, 2000
Tracked Since Feb 18, 2026