← All CVEs

CVE-2000-0884

high · 7.5

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

7.5
CVSS
72.1%
EPSS (exploit prob.)
99th
EPSS percentile
2000-12-19
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
microsoftinternet_information_server4.0
microsoftinternet_information_services5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2000-0884