CVE-2000-0630: Medium severity Microsoft Internet Information Server vulnerability
Published Jul 17, 2000
·Updated
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.
Affected Software
2 affected components
Microsoft Internet Information Server=4.0
Microsoft Internet Information Services=5.0
Event History
Jul 17, 2000
CVE Published
04:00 AM
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0630?
CVE-2000-0630 is considered to have a medium severity due to its ability to expose sensitive source code fragments.
2
How do I fix CVE-2000-0630?
To fix CVE-2000-0630, ensure that your IIS servers are upgraded to a patched version or consider disabling the .HTR file extension.
3
Which versions of software are affected by CVE-2000-0630?
CVE-2000-0630 affects Microsoft Internet Information Server versions 4.0 and 5.0.
4
What type of attack does CVE-2000-0630 enable?
CVE-2000-0630 enables remote attackers to read fragments of source code via crafted URLs.
5
Is there a workaround for CVE-2000-0630?
A possible workaround for CVE-2000-0630 includes restricting access to .HTR files by modifying the server configuration.