CVE-2000-0649
LOW 2.6EPSS 76.6%
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
- CVSS v2.0
- 2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N - EPSS
- 76.56% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2000-08-03
- Updated
- 2024-08-08
Proof-of-concept exploits (3)
- Downgraderz/PoC-CVE-2000-06491★ · 2024-06-18
- rafaelh/CVE-2000-06498★ · 2024-04-01
- stevenvegar/cve-2000-06490★ · 2021-10-25