CVE-2000-0071

CVSS 2.0 Score 5 of 10 (medium)

Details

Published Jan 11, 2000
Updated: Nov 20, 2024

Summary

CVE-2000-0071 refers to a vulnerability in IIS 4.0 where a remote attacker can request non-existent files with .ida or .idq extensions. This issue allows the attacker to obtain the real pathname of the document root, potentially granting unauthorized access to sensitive information. This vulnerability can pose a significant risk if not addressed promptly, as it enables an attacker to explore the server's file system and potentially gain unauthorized access to sensitive data. IIS 4.0 users are strongly advised to apply the available patches or upgrades to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share