cbcvebase.
CVE-2000-0408
published 2000-05-11

CVE-2000-0408: IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the…

PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
55.86%
98.9th percentile
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.

Affected

2 ranges
VendorProductVersion rangeFixed in
microsoftinternet_information_server
microsoftinternet_information_services

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/19907-1.exe
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/19907.zip
  • Look for abnormally long URLs containing a large number of file extension sequences (e.g., repeated dot-separated segments) in IIS HTTP access logs, which is the hallmark of this DoS attack.
  • Monitor IIS 4.0/5.0 host CPU usage for sudden spikes to 100% correlated with inbound HTTP requests containing malformed extension data, as the vulnerability causes CPU exhaustion until the URL is fully processed.
  • ·Affected versions are IIS 4.0 and 5.0 only; the DoS condition requires restarting the IIS application or waiting for the malformed URL to finish processing before normal service resumes.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.