cbcvebase.
CVE-2002-0074
published 2002-04-22

CVE-2002-0074: Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts…

PriorityP427high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
31.03%
98.1th percentile
Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoproducts_ms02-018
microsoftinternet_information_server
microsoftinternet_information_services

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2002-0074 is a cross-site scripting (XSS) vulnerability in the Help File search facility of IIS 4.0, 5.0, and 5.1. Detection should focus on malicious script injection attempts targeting the IIS Help File search endpoint.
  • ·This vulnerability affects Cisco products and applications installed on Microsoft operating systems that incorporate IIS — the root cause is IIS itself, not a defect in the Cisco product or application.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.