cbcvebase.
CVE-2002-0073
published 2002-04-22

CVE-2002-0073: The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a…

PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
53.05%
98.9th percentile
The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoproducts_ms02-018
microsoftinternet_information_server
microsoftinternet_information_services

Detection & IOCsextracted from sources · hover to see the quote

  • FTP session denial of service triggered by a specially crafted status request containing glob characters against IIS FTP service
  • ·Vulnerability affects IIS FTP service versions 4.0, 5.0, and 5.1; attacker must have already established a valid FTP session before exploiting
  • ·Cisco products and applications installed on Microsoft operating systems using IIS are also affected; the vulnerability is in IIS itself, not the Cisco product
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.