MEDIUM · 5.0

CVE-2000-0246

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka ...

Vulnerability Description

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftCommercial Internet System2.0
MicrosoftInternet Information Server4.0
MicrosoftInternet Information Services5.0
MicrosoftProxy Server2.0
MicrosoftSite Server3.0
MicrosoftSite Server Commerce3.0

References

FAQ

What is CVE-2000-0246?

CVE-2000-0246 is a vulnerability with a CVSS score of 5.0 (MEDIUM). IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka ...

How severe is CVE-2000-0246?

CVE-2000-0246 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2000-0246?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Commercial Internet System, Microsoft Internet Information Server, Microsoft Internet Information Services, Microsoft Proxy Server, Microsoft Site Server.