CVE-2001-0004

CWE-4304 documents4 sources
Severity
5.0MEDIUM
EPSS
74.2%
top 1.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateApr 30

Description

IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

🔴Vulnerability Details

2
GHSA
GHSA-mr3v-pmm4-26v3: IIS 52022-04-30
CVEList
CVE-2001-0004: IIS 52001-09-18

📐Framework References

1
CWE
Deployment of Wrong Handler
CVE-2001-0004 (MEDIUM CVSS 5) | IIS 5.0 and 4.0 allows remote attac | cvebase.io