Information Disclosure via IIS FrontPage Extensions by Microsoft
CVE-2000-0413
Currently unrated
What is CVE-2000-0413?
The shtml.exe program within the FrontPage extensions of Microsoft's Internet Information Services (IIS) versions 4.0 and 5.0 is susceptible to an information disclosure vulnerability. By sending a request for a non-existent file, remote attackers can generate an error message that inadvertently reveals the physical file paths of sensitive HTML, HTM, ASP, and SHTML files on the server. This exposure could lead to further exploitation or unauthorized access to critical server information.