CVE-2000-0413: The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the ph

Published n/a Updated 2026-08-21T04:31:02.064Z

Summary

The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.

Severity

UNKNOWN

Source Attribution

Source: NVD · Updated: 2026-08-21T04:31:02.064Z · Confidence: high

Impact

Based on CVSS vector: n/a — assess confidentiality, integrity, and availability impact via the official vector documentation.

Affected Software

Fix

Upgrade affected software to the fixed version identified above. Apply vendor patches and monitor advisories before exposed systems go unpatched.

References