CVE-2000-0024

3 documents3 sources
Severity
6.4MEDIUM
EPSS
12.0%
top 6.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21
Latest updateApr 30

Description

IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-h3mj-3v87-42wc: IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape charac2022-04-30
CVEList
CVE-2000-0024: IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape charac2000-04-25
CVE-2000-0024 (MEDIUM CVSS 6.4) | IIS does not properly canonicalize | cvebase.io