PT-2000-1643 · Microsoft · Frontpage 2000 Server Extensions
Published
2000-10-20
·
Updated
2017-07-12
·
CVE-2000-0710
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft FrontPage 2000 Server Extensions version 1.1
Description
The issue allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name. This is due to a flaw in the shtml.exe component.
Recommendations
For Microsoft FrontPage 2000 Server Extensions version 1.1, consider restricting access to the shtml.exe component until a fix is available. As a temporary workaround, avoid using standard DOS device names in URLs to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frontpage 2000 Server Extensions