The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.543
EPSS Ranking 97.8%