First published: Fri Jul 14 2000(Updated: )
An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =3.0 | |
Microsoft Internet Information Services | =4.0 | |
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0631 has a high severity due to its potential to cause denial of service to affected IIS servers.
To fix CVE-2000-0631, it is recommended to upgrade to a newer, patched version of Internet Information Services.
CVE-2000-0631 affects Microsoft Internet Information Services versions 3.0, 4.0, and 5.0.
CVE-2000-0631 facilitates denial of service attacks by allowing remote access to a vulnerable administrative script.
A possible workaround for CVE-2000-0631 includes disabling the vulnerable script or limiting access to it.