Back

CVE-2000-0304

Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.

Published: May 10, 2000 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft internet_information_server 4.0
microsoft internet_information_services 5.0

GitHub Security Advisory GHSA-7qq3-2c7j-qq7w

Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 51.69%

Top 2% most likely to be exploited

Threat Score 35.5 / 100

Data Sources

NVD EPSS GitHub