CVE-2000-0710

Microsoft FrontPage 2000 Server Extensions - Physical Path Disclosure via Invalid URL

Title source: llm
STIX 2.1

Description

The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.

References (3)

Core 3
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1608
Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html

Scores

EPSS 0.2638
EPSS Percentile 97.8%

Details

Status published
Products (1)
microsoft/frontpage
Published Oct 20, 2000
Tracked Since Feb 18, 2026