Internet Information Services Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2000-0649 - Vulnerability Database

Internet Information Services Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2000-0649

Low
Reference: CVE-2000-0649
Title: Internet Information Services Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.