CVE-2000-0071
CVSS 2.0 Score 5 of 10 (medium)
Details
Summary
CVE-2000-0071 refers to a vulnerability in IIS 4.0 where a remote attacker can request non-existent files with .ida or .idq extensions. This issue allows the attacker to obtain the real pathname of the document root, potentially granting unauthorized access to sensitive information. This vulnerability can pose a significant risk if not addressed promptly, as it enables an attacker to explore the server's file system and potentially gain unauthorized access to sensitive data. IIS 4.0 users are strongly advised to apply the available patches or upgrades to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft IIS
Affected Vendors
- Microsoft