CVE-2000-0408

Internet Information Server 4.05 and 5.0 - Denial of Service via Malformed Extension Data in URL

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0408. PoCs published by Ussr Labs.

AI-analyzed exploit summary The provided text describes a DoS vulnerability in Microsoft IIS 4.0/5.0 where a malformed URL causes CPU exhaustion. No actual exploit code is present, only references to external binaries.

Description

IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ussr Labs · textdoswindows
https://www.exploit-db.com/exploits/19907

The provided text describes a DoS vulnerability in Microsoft IIS 4.0/5.0 where a malformed URL causes CPU exhaustion. No actual exploit code is present, only references to external binaries.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft IIS 4.0/5.0
No auth needed
Prerequisites: Network access to target IIS server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1190
Vendor Advisory vendor-advisory x_refsource_mskb
http://www.microsoft.com/technet/support/kb.asp?ID=260205
Various Sources x_refsource_misc
http://www.ussrback.com/labs40.html

Scores

EPSS 0.5796
EPSS Percentile 99.0%

Details

Status published
Products (2)
microsoft/internet_information_server 4.0
microsoft/internet_information_services 5.0
Published May 11, 2000
Tracked Since Feb 18, 2026