VulnerabilityModified
CVE-2000-0649
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
LOW 2.6EPSS 76.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 76.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 76.56% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/internet information server · microsoft/internet information services
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0025.htmlExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/1499Exploit, Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0025.htmlExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/1499Exploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.