VDB
CVE-2001-0004
CVE-2001-0004
PUBLISHED
CVSS 5 MEDIUM
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.
EPSS 74.23% · 98.9th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
74.23%
98.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| microsoft | internet_information_server | 4.0 |
| microsoft | internet_information_services | 5.0 |
Timeline
- Feb 12, 2001 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Aug 19, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- 2313 vdb
- iis-read-files(5903) vdb
- MS01-004 vendor-advisory
- 20010108 IIS 5.0 allows viewing files using %3F+.htr mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2001-0004 advisory