Back

CVE-2000-0886

IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.

Published: Dec 19, 2000 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft internet_information_server 4.0
microsoft internet_information_services 5.0

GitHub Security Advisory GHSA-8x76-gx9r-885w

IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 89.22%

Top 0% most likely to be exploited

Threat Score 66.8 / 100

Data Sources

NVD EPSS GitHub