CVE-2000-0413

IIS 4.0-5.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Frankie Zie · textremotewindows
https://www.exploit-db.com/exploits/19897

References (2)

Core 2
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-05/0084.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1174

Scores

EPSS 0.5939
EPSS Percentile 98.3%

Details

Status published
Products (3)
microsoft/frontpage
microsoft/internet_information_server 4.0
microsoft/internet_information_services 5.0
Published May 06, 2000
Tracked Since Feb 18, 2026