CVE-2000-0884 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 63.3% (pctl 99)
Patch early
A public exploit exists.
Description
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 63.28% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2000-12-19 |
| Last modified | 2026-09-23 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | internet information server |
| microsoft | internet information services |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (6) | 2000-11-18 |
| exploit-db | Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (9) | 2000-11-18 |
| exploit-db | Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (7) | 2000-11-18 |
| exploit-db | Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (8) | 2000-11-18 |
| exploit-db | Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (2) | 2000-10-21 |
| exploit-db | Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (1) | 2000-10-17 |
| exploit-db | Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (3) | 2000-10-17 |
| exploit-db | Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (4) | 2000-10-17 |
| exploit-db | Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (5) | 2000-10-17 |
References
- http://www.osvdb.org/436
- http://www.securityfocus.com/bid/1806
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-078
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5377
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A44
- http://www.osvdb.org/436
- http://www.securityfocus.com/bid/1806
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-078
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5377
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A44
→ the Explorer · watch your stack · NVD