CVE-2000-0457: ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large nu

Published n/a Updated 2026-08-21T04:31:02.189Z

Summary

ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.

Severity

UNKNOWN

Source Attribution

Source: NVD · Updated: 2026-08-21T04:31:02.189Z · Confidence: high

Impact

Based on CVSS vector: n/a — assess confidentiality, integrity, and availability impact via the official vector documentation.

Affected Software

Fix

Upgrade affected software to the fixed version identified above. Apply vendor patches and monitor advisories before exposed systems go unpatched.

References