CVE-2002-0073
published 2002-04-22CVE-2002-0073: The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
53.05%
98.9th percentile
The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | products_ms02-018 | — | — |
| microsoft | internet_information_server | — | — |
| microsoft | internet_information_services | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →FTP session denial of service triggered by a specially crafted status request containing glob characters against IIS FTP service ↗
- ·Vulnerability affects IIS FTP service versions 4.0, 5.0, and 5.1; attacker must have already established a valid FTP session before exploiting ↗
- ·Cisco products and applications installed on Microsoft operating systems using IIS are also affected; the vulnerability is in IIS itself, not the Cisco product ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
vendor_cisco·2002-04-15
CVE-2002-0071 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
This advisory describes a vulnerability that affects Cisco products and
applications that are installed on Microsoft operating systems incorporating
the use of the Internet Information Server (IIS), and is based on the
vulnerability of IIS, not due to a defect of the Cisco product or application.
A number of vulnerabilities were discovered that enables an attacker to
execute arbitrary code or perform a denial of service against the server. These
vulnerabilities were discovered and publicly announced by Microsoft in their
Microsoft Security Bulletin MS02-018.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020415-ms02-018.
Cisco
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
vendor_cisco
CVE-2002-0073 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
CVE-2002-0073: Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
This advisory describes a vulnerability that affects Cisco products and applications that are installed on Microsoft operating systems incorporating the use of the Internet Information Server (IIS), and is based on the vulnerability of IIS, not due to a defect of the Cisco product or application. A number of vulnerabilities were discovered that enables an attacker to execute arbitrary code or perform a denial of service against the server. These vulnerabilities were discovered and publicly announced by Microsoft in their Microsoft Security Bulletin MS02-018. This advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020415-ms02-018 .
GHSA
GHSA-fhmg-928x-jg98: The FTP service in Internet Information Server (IIS) 4
ghsa_unreviewed·2022-04-30
CVE-2002-0073 [MEDIUM] GHSA-fhmg-928x-jg98: The FTP service in Internet Information Server (IIS) 4
The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0023.htmlhttp://marc.info/?l=bugtraq&m=101901273810598&w=2http://www.cert.org/advisories/CA-2002-09.htmlhttp://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtmlhttp://www.digitaloffense.net/msftpd/advisory.txthttp://www.iss.net/security_center/static/8801.phphttp://www.kb.cert.org/vuls/id/412203http://www.osvdb.org/3328http://www.securityfocus.com/bid/4482https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-018https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A24https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A35http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0023.htmlhttp://marc.info/?l=bugtraq&m=101901273810598&w=2http://www.cert.org/advisories/CA-2002-09.htmlhttp://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtmlhttp://www.digitaloffense.net/msftpd/advisory.txthttp://www.iss.net/security_center/static/8801.phphttp://www.kb.cert.org/vuls/id/412203http://www.osvdb.org/3328http://www.securityfocus.com/bid/4482https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-018https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A24https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A35
2002-04-22
Published