CVE-2000-0649: Infoleak
Published Jul 13, 2000
·Updated
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
Affected Software
4 affected components
Microsoft Internet Information Server=3.0
Microsoft Internet Information Server=4.0
Microsoft Internet Information Services=2.0
Microsoft Internet Information Services=5.0
Remediation
Patch Available
Event History
Jul 13, 2000
CVE Published
04:00 AM
Aug 3, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0649?
CVE-2000-0649 is considered to have a medium severity due to its potential to disclose sensitive server information.
2
How do I fix CVE-2000-0649?
To fix CVE-2000-0649, ensure that your IIS server uses a defined realm in basic authentication or consider upgrading to a newer version.
3
What versions of IIS are affected by CVE-2000-0649?
CVE-2000-0649 affects Microsoft Internet Information Server versions 2.0, 3.0, 4.0, and 5.0.
4
Can I exploit CVE-2000-0649 remotely?
Yes, CVE-2000-0649 allows remote attackers to exploit the vulnerability through crafted HTTP requests.
5
What information can be leaked due to CVE-2000-0649?
CVE-2000-0649 can potentially leak the internal IP address of the server to unauthorized users.