IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
Loading...
Loading...
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
July 13, 2000
April 16, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (1 Metasploit module) (1 GitHub PoC) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Test for CVE-2000-0649, and return an IP address if vulnerable
Open source ↗Microsoft IIS 2.0/3.0/4.0/5.0/5.1 - Internal IP Address Disclosure
Open source ↗Microsoft IIS HTTP Internal IP Disclosure
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2000-0649
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.