CVE-2000-0413
MEDIUM 5.0EPSS 43.9%
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 43.89% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2000-06-15
- Updated
- 2024-08-08