CVE-2000-0408: Medium severity microsoft internet information services vulnerability
Published May 11, 2000
·Updated
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.
Affected Software
2 affected components
Microsoft Internet Information Services=5.0
Microsoft Internet Information Server=4.0
Event History
May 11, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jul 12, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0408?
CVE-2000-0408 is classified as a denial of service vulnerability that can disrupt the operation of affected systems.
2
How do I fix CVE-2000-0408?
To fix CVE-2000-0408, upgrading to a more secure version of IIS or applying relevant patches from Microsoft is recommended.
3
What versions of IIS are affected by CVE-2000-0408?
CVE-2000-0408 affects Internet Information Server 4.0 and 5.0.
4
What type of attack does CVE-2000-0408 involve?
CVE-2000-0408 involves an attack through a long and complex URL that exploits the way IIS handles file extensions.
5
Can CVE-2000-0408 be exploited remotely?
Yes, CVE-2000-0408 can be exploited by remote attackers to cause a denial of service.