Vulnerabilities > CVE-2000-0413 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | FrontPage 2000,IIS 4.0/5.0 Server Extensions Path Disclosure Vulnerability. CVE-2000-0413. Remote exploit for windows platform |
id | EDB-ID:19897 |
last seen | 2016-02-02 |
modified | 2000-05-06 |
published | 2000-05-06 |
reporter | Frankie Zie |
source | https://www.exploit-db.com/download/19897/ |
title | FrontPage 2000,IIS 4.0/5.0 Server Extensions Path Disclosure Vulnerability |
Nessus
NASL family | Web Servers |
NASL id | FRONTPAGE_SHTML.NASL |
description | The version of FrontPage Extensions running on the remote host has an information disclosure vulnerability. Using a non-existent file as an argument to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10405 |
published | 2000-05-10 |
reporter | This script is Copyright (C) 2000-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10405 |
title | Microsoft IIS FrontPage Server Extensions (FPSE) shtml.exe Path Disclosure |
code |
|