CVE-2000-0114 describes an information disclosure vulnerability in Microsoft FrontPage Server Extensions, specifically affecting Microsoft Internet Information Server. Remote attackers can exploit this flaw by sending an RPC POST request to shtml.dll to determine the name of the anonymous account. With a CVSS score of 5.0 (Medium), this vulnerability has a network attack vector, low attack complexity, and results in a partial confidentiality impact without affecting integrity or availability. While there is no Metasploit or ExploitDB module, Nuclei templates exist, and there's some community discussion, though it's not on the CISA KEV catalog and has no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_server:3.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_server:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.