5
CVSSv2

CVE-2000-0408

Published: 11/05/2000 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

IIS 4.05 and 5.0 allow remote malicious users to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet information server 4.0

microsoft internet information services 5.0

Exploits

source: wwwsecurityfocuscom/bid/1190/info Sending a specially crafted URL containing malformed file extension information to Microsoft IIS 40/50 will consume CPU usage until it reaches 100% which will halt the program's services Restarting the application or waiting until the URL is processed will be required in order to regain normal ...