First published: Thu May 11 2000(Updated: )
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services (IIS) | =5.0 | |
Microsoft Internet Information Services | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0408 is classified as a denial of service vulnerability that can disrupt the operation of affected systems.
To fix CVE-2000-0408, upgrading to a more secure version of IIS or applying relevant patches from Microsoft is recommended.
CVE-2000-0408 affects Internet Information Server 4.0 and 5.0.
CVE-2000-0408 involves an attack through a long and complex URL that exploits the way IIS handles file extensions.
Yes, CVE-2000-0408 can be exploited by remote attackers to cause a denial of service.