CVE-2000-0246
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
- Affected products
- Iis
- Microsoft Commercial Internet System
- = 2.0, 2.5
- Microsoft Internet Information Server
- = 4.0
- Microsoft Internet Information Services
- = 5.0
- Microsoft Proxy Server
- = 2.0
- Microsoft Site Server
- = 3.0
- Microsoft Site Server Commerce
- = 3.0
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 80.0% (100th percentile)
- NVD status
- Modified
- Published
- 2000-06-02
CVE-2000-0246 at NVD
1 known exploit for CVE-2000-0246
Proof-of-concept code and exploit modules indexed by Sploitus