CVE-2000-0024

Published: 1999-12-21

Description

IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.

Severity

Overall Severity: N/A

CVSS Metrics

Type Score Severity Vector

Affected Products

microsoft - internet_information_server

Affected Versions:

microsoft - site_server

Affected Versions:

microsoft - site_server_commerce

Affected Versions:

References

Neural Processor Active