First published: Tue Dec 19 2000(Updated: )
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =4.0 | |
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0884 is considered a critical vulnerability that allows remote attackers to access files outside of the web root.
To fix CVE-2000-0884, upgrade to a newer version of Microsoft Internet Information Services that does not have this vulnerability.
CVE-2000-0884 affects Microsoft Internet Information Services version 4.0 and 5.0.
Using CVE-2000-0884, attackers can read unauthorized documents and potentially execute arbitrary commands on the server.
As a workaround for CVE-2000-0884, configure proper permission settings and avoid using UNICODE encoding in URLs.