CVE-2000-1090: Medium severity Microsoft Internet Information Server vulnerability
Published Feb 2, 2001
·Updated
Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.
Affected Software
2 affected components
Microsoft Internet Information Server=4.0
Microsoft Internet Information Server=5.0
Event History
Feb 2, 2001
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability severity of CVE-2000-1090?
CVE-2000-1090 has a medium severity level due to the potential for source code disclosure.
2
How can I mitigate CVE-2000-1090?
To mitigate CVE-2000-1090, ensure your IIS server is updated to a non-Far East edition or apply available patches.
3
Which versions of Microsoft IIS are affected by CVE-2000-1090?
CVE-2000-1090 affects Microsoft IIS versions 4.0 and 5.0 specifically for Far East editions.
4
What type of attacks can exploit CVE-2000-1090?
Remote attackers can exploit CVE-2000-1090 to read the source code of parsed pages through a specially crafted URL.
5
Is CVE-2000-1090 specific to a geographic region?
Yes, CVE-2000-1090 is specific to the Far East editions of Microsoft IIS.