CVE-2001-0004
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 28.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 28.21% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet information server · microsoft/internet information services
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=97897954625305&w=2
- http://www.securityfocus.com/bid/2313
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5903
- http://marc.info/?l=bugtraq&m=97897954625305&w=2
- http://www.securityfocus.com/bid/2313
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5903
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.