CVE Vulnerabilities

CVE-2000-0770

Published: Oct 20, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the File Permission Canonicalization vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Internet_information_serverMicrosoft4.0 (including)4.0 (including)
Internet_information_servicesMicrosoft5.0 (including)5.0 (including)

References