Back

CVE-2000-0024

IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.

Published: Dec 21, 1999 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
microsoft internet_information_server 4.0
microsoft site_server 3.0
microsoft site_server_commerce 3.0

GitHub Security Advisory GHSA-h3mj-3v87-42wc

IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 12.22%

Top 4% most likely to be exploited

Threat Score 29.3 / 100

Data Sources

NVD EPSS GitHub