Vulnerability Name: | CVE-2000-0649 (CCN-5106) | ||||||||
Assigned: | 2000-07-13 | ||||||||
Published: | 2000-07-13 | ||||||||
Updated: | 2020-11-23 | ||||||||
Summary: | IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: NTBUGTRAQ Type: Exploit, Patch, Vendor Advisory 20000713 IIS4 Basic authentication realm issue Source: MITRE Type: CNA CVE-2000-0649 Source: CCN Type: NTBugTraq Mailing List, Thu, 13 Jul 2000 11:34:25 IIS4 Basic authentication realm issue Source: CCN Type: OSVDB ID: 630 Microsoft IIS Multiple Malformed Header Field Internal IP Address Disclosure Source: BID Type: Exploit, Patch, Vendor Advisory 1499 Source: CCN Type: BID-1499 Microsoft IIS Internal IP Address Disclosure Vulnerability Source: XF Type: UNKNOWN iis-internal-ip-disclosure(5106) Source: CCN Type: Microsoft Knowledge Base Article 218180 Internet Information Server Returns IP Address in HTTP Header (Content-Location) Source: CCN Type: Rapid7 Vulnerability and Exploit Database [05-30-2018] Microsoft IIS HTTP Internal IP Disclosure | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |