CVE-2000-0126
CVSS 2.0 Score 5.0 of 10 (medium)
Details
Summary
CVE-2000-0126 is a vulnerability affecting Internet Information Services (IIS) versions 3 and 4. Attackers can exploit this issue by using Specific Sample Internet Data Query (IDQ) scripts to read sensitive files on the targeted system. The vulnerability arises due to insufficient input validation of IDQ scripts, allowing attackers to execute a "dot dot" attack, thereby gaining unauthorized access to files outside the intended directory. This security weakness poses a significant risk, particularly in enterprise environments, as it can lead to the exposure of confidential information. To mitigate this issue, administrators are advised to update their IIS installation, restrict access to IDQ scripts, and practice secure coding.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft IIS
Affected Vendors
- Microsoft