Loading
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.
Use Microsoft vendor hub and Internet Information Server product page to widen CVE-2000-0886 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2008-0075, CVE-2009-3023 and CVE-2010-1256 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.