First published: Tue Dec 21 1999(Updated: )
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =4.0 | |
Microsoft Site Server Commerce | =3.0 | |
Microsoft Commerce Server | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0024 has a high severity rating due to the potential for remote attackers to bypass access restrictions.
To fix CVE-2000-0024, apply the latest security patches provided by Microsoft for affected versions.
CVE-2000-0024 affects Microsoft Internet Information Server 4.0 and Microsoft Site Server 3.0.
Not addressing CVE-2000-0024 can lead to unauthorized access to restricted resources, potentially compromising sensitive data.
While CVE-2000-0024 is a historical vulnerability, it remains relevant for systems still running affected versions of the software.