CVE-2000-0380
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.
- Affected products
- Cisco Ios
- Cisco Ios
- = 11.1, 11.2, 11.2\(4\)f1, 11.2\(8\), 11.2\(8\)p, 11.2\(9\)p, 11.2\(9\)xa, 11.2\(10\), 11.2\(10\)bc, 11.2\(17\), 11.2p, 11.3, 11.3\(1\), 11.3\(1\)ed, 11.3\(1\)t, 11.3t, 12.0, 12.0\(1\)w, 12.0\(1\)xa3, 12.0\(1\)xb, 12.0\(1\)xe, 12.0\(2\), 12.0\(2\)xc, 12.0\(2\)xd, 12.0\(2\)xf, 12.0\(2\)xg, 12.0\(3\)t2, 12.0\(4\), 12.0\(4\)s, 12.0\(4\)t, 12.0\(5\), 12.0\(5\)t1, 12.0\(6\), 12.0\(7\)t, 12.0\(8\), 12.0\(9\)s, 12.0db, 12.0s, 12.0t
- Fix
- Available
- CVSS 2.0
- 7.1 HIGH
- EPSS
- 35.0% (98th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2000-07-12
CVE-2000-0380 at NVD
3 known exploits for CVE-2000-0380
Proof-of-concept code and exploit modules indexed by Sploitus