CVE-2000-0457
CVSS 2.0 Score 7.5 of 10 (high)
Details
Published May 11, 2000
Updated: Nov 20, 2024
Summary
CVE-2000-0457 is a vulnerability affecting the ISM.DLL component in Internet Information Services (IIS) 4.0 and 5.0. An attacker can exploit this issue by making a request for a file and appending a large number of encoded spaces (%20) followed by the .htr extension. By doing so, the attacker can read the contents of arbitrary files on the targeted system. This vulnerability, also known as the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" issue, poses a significant risk to IIS servers if not properly addressed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft IIS
Affected Vendors
- Microsoft