CVE-2000-0884
67Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 71%
from disclosure to weapon0 days
Published on NVDJan 22
1st PoCOct 17
VulnCheck+1676d
exploitation probability
71%top 1% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
Affected products
n/a · n/apublic PoCs found — 9✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/20298exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/20299exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/20300exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/20301exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/20302exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/189exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/191exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/192exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/190⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.