20000511 Alert: IIS ism.dll exposes file contentsmailing list
http://marc.info/?l=bugtraq&m=95810120719608&w=2 CVE-2000-0457
Microsoft IIS 4.0/5.0 - Malformed Filename Request
Record summary
CVE-2000-0457 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft IIS 4.0/5.0 - Malformed Filename RequestExploitDB exploitby Cerberus Security TeamNot analyzed1 file
References
51193vdb entry
http://www.securityfocus.com/bid/1193 MS00-031Vendor advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-031 iis-ism-file-access(4448)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/4448 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0457