peter bassill · operator
$ cve CVE-2000-0884 JSON

CVE-2000-0884 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 63.3% (pctl 99)

Patch early

A public exploit exists.

Description

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS63.28% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2000-12-19
Last modified2026-09-23

Affected (2)

VendorProduct
microsoftinternet information server
microsoftinternet information services

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD