CVE-2000-0649
low · 2.6IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
2.6
CVSS
76.6%
EPSS (exploit prob.)
100th
EPSS percentile
2000-07-13
Published
AV:N/AC:H/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_information_server | 3.0 |
| microsoft | internet_information_server | 4.0 |
| microsoft | internet_information_services | 2.0 |
| microsoft | internet_information_services | 5.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2000-0649