CVE-2000-0025
published 1999-12-21CVE-2000-0025: IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
34.85%
98.2th percentile
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_information_server | — | — |
| microsoft | site_server | — | — |
| microsoft | site_server_commerce | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft IIS 4.0 ASP File Source information disclosure (MS99-058 / XFDB-4392)
vuldb·2026-04-20·CVSS 5.0
CVE-2000-0025 [MEDIUM] Microsoft IIS 4.0 ASP File Source information disclosure (MS99-058 / XFDB-4392)
A vulnerability, which was classified as critical, has been found in Microsoft IIS 4.0. This impacts an unknown function of the component ASP File Handler. This manipulation causes information disclosure (Source).
The identification of this vulnerability is CVE-2000-0025. It is possible to initiate the attack remotely. There is no exploit available. Due to its background and reception, this vulnerability has an historic impact.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-34rm-j4gj-85h8: IIS 4
ghsa_unreviewed·2022-04-30
CVE-2000-0025 [MEDIUM] GHSA-34rm-j4gj-85h8: IIS 4
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ238606http://www.osvdb.org/8098https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-058http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ238606http://www.osvdb.org/8098https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-058
1999-12-21
Published