CVE-2000-0304
CVSS 2.0 Score 5.0 of 10 (medium)
Details
Published May 10, 2000
Updated: Nov 20, 2024
Summary
CVE-2000-0304 is a denial-of-service vulnerability affecting Microsoft IIS 4.0 and 5.0 servers with the IISADMPWD virtual directory installed. A remote attacker can cause a service disruption by sending a malformed request to the inetinfo.exe program. This vulnerability, also known as the "Undelimited .HTR Request" issue, allows an attacker to manipulate the parsing of .HTR files, leading to memory exhaustion and ultimately crashing the server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Microsoft IIS
Affected Vendors
- Microsoft