Back

CVE-2001-0004

IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.

Published: Feb 12, 2001 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft internet_information_server 4.0
microsoft internet_information_services 5.0

GitHub Security Advisory GHSA-mr3v-pmm4-26v3

IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 74.23%

Top 1% most likely to be exploited

Threat Score 52.3 / 100

Data Sources

NVD EPSS GitHub