PoC Index

CVE-2000-0413

MEDIUM 5.0EPSS 43.9%

The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
43.89% chance of exploitation in the next 30 days, 99th percentile
Published
2000-06-15
Updated
2024-08-08

ExploitDB entries (1)

References

Related