CVE-2000-0413 describes a full path disclosure vulnerability in the shtml.exe component of Microsoft FrontPage extensions for IIS 4.0 and 5.0. An unauthenticated remote attacker can determine the physical path of various web files by requesting a non-existent file, causing an error message to reveal the server's directory structure. This vulnerability has a CVSS score of 5.0 (Medium) due to its network-based attack vector and low attack complexity, primarily impacting confidentiality. While not listed in CISA's KEV catalog or having significant community discussion, an ExploitDB entry exists, indicating public exploit code for this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:frontpage:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_server:4.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.