CVE-2000-0886: High severity Microsoft Internet Information Server vulnerability
Published Dec 19, 2000
·Updated
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.
Affected Software
2 affected components
Microsoft Internet Information Server=4.0
Microsoft Internet Information Services=5.0
Event History
Dec 19, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0886?
CVE-2000-0886 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2000-0886?
To fix CVE-2000-0886, you should upgrade to a newer version of Microsoft Internet Information Services that is not affected by this vulnerability.
3
Which versions of IIS are affected by CVE-2000-0886?
CVE-2000-0886 affects Microsoft Internet Information Services 5.0 and Internet Information Server 4.0.
4
What types of attacks can be executed using CVE-2000-0886?
Attackers can exploit CVE-2000-0886 to execute arbitrary commands on the server through crafted requests.
5
When was CVE-2000-0886 discovered?
CVE-2000-0886 was disclosed in the year 2000.