7.5
CVE-2000-0884
- EPSS 72.07%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 23.09.2026 10:10:00
- Erkennungen
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Information Server Version 4.0
Microsoft ≫ Internet Information Services Version 5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 72.07% | 0.994 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://www.osvdb.org/436
http://www.securityfocus.com/bid/1806
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-078
https://exchange.xforce.ibmcloud.com/vulnerabilities/5377
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A44