CVE-2000-0457

Internet Information Server 4.0-5.0 - Unauthenticated Arbitrary File Read via .HTR Extension with Encoded Spaces

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0457. PoCs published by Cerberus Security Team.

AI-analyzed exploit summary This exploit describes a vulnerability in Microsoft IIS 4.0/5.0 where requesting a file with a .htr extension preceded by approximately 230 '%20' characters can reveal the source of the file. The vulnerability is due to the ISM.DLL ISAPI application incorrectly handling the .htr file extension.

Description

ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Cerberus Security Team · textremotewindows
https://www.exploit-db.com/exploits/19908

This exploit describes a vulnerability in Microsoft IIS 4.0/5.0 where requesting a file with a .htr extension preceded by approximately 230 '%20' characters can reveal the source of the file. The vulnerability is due to the ISM.DLL ISAPI application incorrectly handling the .htr file extension.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Microsoft IIS 4.0/5.0
No auth needed
Prerequisites: Target server running Microsoft IIS 4.0/5.0 · ISM.DLL not already loaded into memory or server restart required
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=95810120719608&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/4448
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1193

Scores

EPSS 0.5275
EPSS Percentile 98.8%

Details

Status published
Products (2)
microsoft/internet_information_server 4.0
microsoft/internet_information_services 5.0
Published May 11, 2000
Tracked Since Feb 18, 2026