CVE-2000-0408
Internet Information Server 4.05 and 5.0 - Denial of Service via Malformed Extension Data in URL
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-0408. PoCs published by Ussr Labs.
AI-analyzed exploit summary The provided text describes a DoS vulnerability in Microsoft IIS 4.0/5.0 where a malformed URL causes CPU exhaustion. No actual exploit code is present, only references to external binaries.
Description
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Ussr Labs · textdoswindows
https://www.exploit-db.com/exploits/19907
The provided text describes a DoS vulnerability in Microsoft IIS 4.0/5.0 where a malformed URL causes CPU exhaustion. No actual exploit code is present, only references to external binaries.
Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target:
Microsoft IIS 4.0/5.0
No auth needed
Prerequisites:
Network access to target IIS server
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1190
Vendor Advisory vendor-advisory
x_refsource_mskb
http://www.microsoft.com/technet/support/kb.asp?ID=260205
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-030
Various Sources x_refsource_misc
http://www.ussrback.com/labs40.html
Scores
EPSS
0.5796
EPSS Percentile
99.0%
Details
Status
published
Products (2)
microsoft/internet_information_server
4.0
microsoft/internet_information_services
5.0
Published
May 11, 2000
Tracked Since
Feb 18, 2026