CVE-2000-0710
Microsoft FrontPage 2000 Server Extensions - Physical Path Disclosure via Invalid URL
Title source: llmDescription
The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1608
Patch, Vendor Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html
Scores
EPSS
0.2638
EPSS Percentile
97.8%
Details
Status
published
Products (1)
microsoft/frontpage
Published
Oct 20, 2000
Tracked Since
Feb 18, 2026