peter bassill · operator
$ cve CVE-2000-0413 JSON

CVE-2000-0413 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 43.9% (pctl 99)

Patch early

A public exploit exists.

Description

The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS43.89% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2000-05-06
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftfrontpage
microsoftinternet information server
microsoftinternet information services

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD