CVE-2000-0884: High severity Microsoft Internet Information Server vulnerability
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0884?
CVE-2000-0884 is considered a critical vulnerability that allows remote attackers to access files outside of the web root.
How do I fix CVE-2000-0884?
To fix CVE-2000-0884, upgrade to a newer version of Microsoft Internet Information Services that does not have this vulnerability.
What are the affected versions in CVE-2000-0884?
CVE-2000-0884 affects Microsoft Internet Information Services version 4.0 and 5.0.
What type of attacks can be executed using CVE-2000-0884?
Using CVE-2000-0884, attackers can read unauthorized documents and potentially execute arbitrary commands on the server.
Is there a workaround for CVE-2000-0884?
As a workaround for CVE-2000-0884, configure proper permission settings and avoid using UNICODE encoding in URLs.