CVE-2000-0025: Medium severity Microsoft Internet Information Server vulnerability
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Rename or remove any virtual directories whose names include file-extension-like substrings (for example ".com", ".exe", ".sh", ".cgi", ".dll"); ensure ASP files are not stored in virtual directories with those names to prevent source disclosure.
Microsoft Internet Information Services (IIS) 4.0 virtual directory naming = do not use names containing extensions such as .com, .exe, .sh, .cgi, .dll - Configuration
On systems integrating Commerce Server or Site Server Commerce with IIS, ensure virtual directory names do not include extensions like ".com", ".exe", ".sh", ".cgi", or ".dll"; rename or remove such directories and relocate any ASP files.
Microsoft Commerce Server / Microsoft Site Server Commerce virtual directory naming = do not use names containing extensions such as .com, .exe, .sh, .cgi, .dll - Operational
Audit affected servers (IIS 4.0, Site Server 3.0, and systems running Microsoft Commerce Server / Site Server Commerce) for virtual directory names containing ".com", ".exe", ".sh", ".cgi", or ".dll" and remediate by renaming/removing directories and relocating ASP files; repeat audit after changes to confirm remediation.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0025?
CVE-2000-0025 is classified as a medium severity vulnerability.
How do I fix CVE-2000-0025?
To fix CVE-2000-0025, ensure that virtual directories do not use extensions like .com, .exe, .sh, .cgi, or .dll.
Who is affected by CVE-2000-0025?
CVE-2000-0025 affects users of Microsoft Internet Information Server 4.0 and Microsoft Site Server 3.0.
What type of attack can exploit CVE-2000-0025?
CVE-2000-0025 can be exploited through remote attacks that read the source code of ASP files.
What systems should be monitored for CVE-2000-0025?
Systems running Microsoft IIS 4.0 and Site Server 3.0 should be monitored for CVE-2000-0025 vulnerabilities.