First published: Mon Jul 17 2000(Updated: )
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =4.0 | |
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0630 is considered to have a medium severity due to its ability to expose sensitive source code fragments.
To fix CVE-2000-0630, ensure that your IIS servers are upgraded to a patched version or consider disabling the .HTR file extension.
CVE-2000-0630 affects Microsoft Internet Information Server versions 4.0 and 5.0.
CVE-2000-0630 enables remote attackers to read fragments of source code via crafted URLs.
A possible workaround for CVE-2000-0630 includes restricting access to .HTR files by modifying the server configuration.