PT-2000-1228 · Microsoft · Iis

Published

2000-03-30

·

Updated

2018-10-30

·

CVE-2000-0246

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IIS versions 4.0 through 5.0
Description The issue arises from improper ISAPI extension processing when a virtual directory is mapped to a UNC share. This allows remote attackers to read the source code of ASP and other files.
Recommendations For IIS versions 4.0 through 5.0, consider remapping virtual directories to local paths instead of UNC shares to prevent exploitation. Additionally, restrict access to sensitive files and directories to minimize the risk of source code disclosure.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0246

Affected Products

Iis