Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2000-1090

EPSS 12.52% · P94
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2000-1090

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft IIS远东版畸形编码字符远程泄漏文件内容漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IIS是一款Windows NT/2000系统自带的的Web服务器软件,由Microsoft公司开发维护。IIS支持对一些特定文件名后缀(如.ASP、.IDC、.HTR)的文件请求执行进一步的处理,当服务器接到此类文件的请求时,每种后缀的文件由一个特定的DLL文件处理。ISM.DLL用于处理.HTR、.STM、.IDC为后缀的文件请求。 NSFOCUS安全小组发现微软IIS 4.0/5.0(远东版本)在处理包含不完整的双字节编码字符的HTTP请求时存在一个安全漏洞,导致WEB目录下的文件内容被泄漏给远程攻
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2000-1090

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2000-1090

登录查看更多情报信息。

Same Patch Batch · n/a · 2001-02-02 · 45 CVEs total

CVE-2001-0082Check Point VPN-1/FireWall服务拒绝漏洞
CVE-2001-0087Itetris特权任意命令执行漏洞
CVE-2001-0086Subscribe-Me Lite管理访问漏洞
CVE-2001-0088phpWebLog管理员认证绕过漏洞
CVE-2001-0098BEA WebLogic Server Double Dot缓冲区溢出漏洞
CVE-2001-0101fetchmail漏洞
CVE-2001-0102Apple macOS 安全漏洞
CVE-2001-0103CoffeeCup FTP客户端过弱密码加密漏洞
CVE-2001-0104Alt-N MDaemon 'Lock服务器绕过漏洞
CVE-2001-0097Infinite InterChange服务拒绝漏洞
CVE-2001-0084GTK+ 安全漏洞
CVE-2001-0079HP-UX Support Tools Manager (STM)覆盖文件漏洞
CVE-2001-0076ikonboard任意命令执行漏洞
CVE-2001-0075Technote 'filename'变量导致文件泄露漏洞
CVE-2001-0074Technote Inc Technote 'board' 函数文件泄漏漏洞
CVE-2001-0073Security-Enhanced Linux缓冲区溢出漏洞
CVE-2001-0070Upland Solutions 1st Up Mail Server DoS漏洞
CVE-2001-0068Java Mac OS Runtime漏洞
CVE-2001-0067J-Pilot信息泄漏漏洞
CVE-2001-0065bftpd缓冲区溢出漏洞

Showing top 20 of 45 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2000-1090

No comments yet


Leave a comment