CVE Database
/

CVE-2001-0004

Back to search

CVE-2001-0004

Published: Sep 18, 2001

Modified: Aug 8, 2024

PUBLISHED

Description

IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.

VendorProductVersions

n/a

n/a

affected
n/a

References

2313
vdb-entry
x_refsource_BID
iis-read-files(5903)
vdb-entry
x_refsource_XF
MS01-004
vendor-advisory
x_refsource_MS

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now