cbcvebase.
CVE-2002-0071
published 2002-04-22

CVE-2002-0071: Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a…

PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
26.05%
97.7th percentile
Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoproducts_ms02-018
microsoftinternet_information_server
microsoftinternet_information_services

Detection & IOCsextracted from sources · hover to see the quote

filenameism.dll
  • Monitor for HTTP requests targeting HTR scripting endpoints with abnormally long variable names, which indicate exploitation attempts against the ism.dll ISAPI buffer overflow.
  • Identify presence and execution of the ism.dll ISAPI extension on IIS 4.0 and 5.0 servers as an attack surface indicator.
  • ·Vulnerability is in IIS itself (ism.dll ISAPI extension), not in the Cisco product or application installed on top of it. Cisco products are affected only because they are installed on Microsoft operating systems incorporating IIS.
  • ·Affected IIS versions are 4.0 and 5.0 only; scope detection rules accordingly.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.