ID

VAR-200007-0069


CVE

CVE-2000-0631


TITLE

IIS Management Script Service Rejection Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200007-038

DESCRIPTION

An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability. Microsoft IIS 3.0 shipped with a number of HTR scripts, one of which could be used to cause a Denial of Service against the hosting machine. Although these scripts were only distributed with IIS 3.0, they would be retained during upgrade to 4.0 or 5.0 and therefore these versions may be vulnerable if they were installed as an upgrade to 3.0. The vulnerable script is used to browse directories and normally expects a directory name as a variable. If a request with this variable blank is received, the script enters an infinite loop resulting in system resource exhaustion. No further details were made available by Microsoft

Trust: 1.17

sources: NVD: CVE-2000-0631 // BID: 1476

AFFECTED PRODUCTS

vendor:microsoftmodel:internet information serverscope:eqversion:4.0

Trust: 1.6

vendor:microsoftmodel:internet information serverscope:eqversion:3.0

Trust: 1.6

vendor:microsoftmodel:internet information servicesscope:eqversion:5.0

Trust: 1.6

vendor:microsoftmodel:internet information serverscope:eqversion:5.0

Trust: 0.6

vendor:microsoftmodel:iisscope:eqversion:5.0

Trust: 0.3

vendor:microsoftmodel:iis alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:iisscope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:iisscope:eqversion:3.0

Trust: 0.3

sources: BID: 1476 // CNNVD: CNNVD-200007-038 // NVD: CVE-2000-0631

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2000-0631
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200007-038
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2000-0631
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-200007-038 // NVD: CVE-2000-0631

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2000-0631

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200007-038

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200007-038

EXTERNAL IDS

db:BIDid:1476

Trust: 1.9

db:NVDid:CVE-2000-0631

Trust: 1.6

db:MSid:MS00-044

Trust: 0.6

db:BUGTRAQid:20000718 ISBASE SECURITY ADVISORY(SA2000-02)

Trust: 0.6

db:XFid:4951

Trust: 0.6

db:CNNVDid:CNNVD-200007-038

Trust: 0.6

sources: BID: 1476 // CNNVD: CNNVD-200007-038 // NVD: CVE-2000-0631

REFERENCES

url:http://www.securityfocus.com/bid/1476

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=96390444022878&w=2

Trust: 1.0

url:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-044

Trust: 1.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/4951

Trust: 1.0

url:http://xforce.iss.net/static/4951.php

Trust: 0.6

url:http://www.microsoft.com/technet/security/bulletin/ms00-044.asp

Trust: 0.6

url:http://marc.theaimsgroup.com/?l=bugtraq&m=96390444022878&w=2

Trust: 0.6

url:http://www.microsoft.com/technet/security/bulletin/fq00-044.asp

Trust: 0.3

sources: BID: 1476 // CNNVD: CNNVD-200007-038 // NVD: CVE-2000-0631

CREDITS

Details of this vulnerability were released in a Microsoft advisory, MS00-044

Trust: 0.3

sources: BID: 1476

SOURCES

db:BIDid:1476
db:CNNVDid:CNNVD-200007-038
db:NVDid:CVE-2000-0631

LAST UPDATE DATE

2024-08-14T13:51:35.928000+00:00


SOURCES UPDATE DATE

db:BIDid:1476date:2000-07-14T00:00:00
db:CNNVDid:CNNVD-200007-038date:2005-10-12T00:00:00
db:NVDid:CVE-2000-0631date:2018-10-30T16:25:10.357

SOURCES RELEASE DATE

db:BIDid:1476date:2000-07-14T00:00:00
db:CNNVDid:CNNVD-200007-038date:2000-07-14T00:00:00
db:NVDid:CVE-2000-0631date:2000-07-14T04:00:00