Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2000-0951

7 documents4 sources
Severity
5.0MEDIUM
EPSS
49.2%
top 2.22%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 19
Latest updateApr 30

Description

A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vp2g-92rf-r6r2: A misconfiguration in IIS 52022-04-30
CVEList
CVE-2000-0951: A misconfiguration in IIS 52001-01-22

💥Exploits & PoCs

4
Exploit-DB
Microsoft Windows Server 2000 - Internet Key Exchange Denial of Service (1)2001-12-11
Exploit-DB
Microsoft Windows Server 2000 - Internet Key Exchange Denial of Service (2)2001-12-07
Exploit-DB
Microsoft IIS 5.0 - Indexed Directory Disclosure2000-10-04
Exploit-DB
Omnicron OmniHTTPd 1.1/2.4 Pro - Remote Buffer Overflow1999-10-22
CVE-2000-0951 (MEDIUM CVSS 5) | A misconfiguration in IIS 5.0 with | cvebase.io