Vulnerability record · CVE-2000-0126 · published 26 January 2000
CVE-2000-0126: IIS IDQ Scripts Directory Traversal File Disclosure
Microsoft · Internet Information Server
Sample Internet Data Query (IDQ) scripts shipped with IIS 3 and 4 fail to properly filter '..' sequences, allowing directory traversal. A remote attacker can read files outside the intended web content directory. The flaw matters because it exposes server-side files to unauthenticated users over the network.
Description
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file disclosure with a high EPSS percentile, though limited to read-only impact on legacy IIS.
What it is
Sample Internet Data Query (IDQ) scripts shipped with IIS 3 and 4 fail to properly filter '..' sequences, allowing directory traversal. A remote attacker can read files outside the intended web content directory. The flaw matters because it exposes server-side files to unauthenticated users over the network.
Impact
An attacker gains read access to files on the server that the web process can reach, potentially exposing configuration, script or data files. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP requests to the affected IDQ scripts; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded; EPSS is high (0.45661, 98.7th percentile), suggesting meaningful predicted exploitation activity, though the references carry no exploit tags.
What to do
- Apply the vendor patch or upgrade to a supported IIS version, since IIS 3 and 4 are long end-of-life.
- Remove or disable unused sample IDQ scripts from the web root.
- Enforce strict input validation and path canonicalization on any remaining IDQ handling.
- Restrict the web process account's file system read permissions to only required content.
Detection
- Search web logs for requests to .idq files containing '..' or encoded traversal sequences.
- Alert on IDQ requests returning 200 responses for paths outside the web root.
- Monitor for anomalous file reads by the IIS worker process outside content directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2000-0126 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0126), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.