CVE
- Id
- 2286
- CVE No.
- CVE-2000-0710
- Status
- Candidate
- Description
- The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
- Phase
- Proposed (20000921)
- Votes
- ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | NOOP(1) Christey
- Comments
- Christey> [note to self: review comments by Mark Burnett] | Frech> XF:frontpage-ext-device-name-dos(5124)