CVE-2000-0025

3 documents3 sources
Severity
5.0MEDIUM
EPSS
46.0%
top 2.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21
Latest updateApr 30

Description

IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-34rm-j4gj-85h8: IIS 42022-04-30
CVEList
CVE-2000-0025: IIS 42000-03-22
CVE-2000-0025 (MEDIUM CVSS 5) | IIS 4.0 and Site Server 3.0 allow r | cvebase.io