ISAPI Extension Processing Flaw in Microsoft IIS 4.0 and 5.0
CVE-2000-0246
Currently unrated
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 30 March 2000
What is CVE-2000-0246?
The IIS web server versions 4.0 and 5.0 are susceptible to a vulnerability related to ISAPI extension processing when a virtual directory is linked to a UNC share. This flaw permits remote attackers to access and read sensitive source code files, including ASP scripts, thereby compromising the security of the web application and its underlying infrastructure. It's critical for web administrators to implement necessary security measures to mitigate this exposure.