CVE-2002-0075

4 documents4 sources
Severity
7.5HIGH
EPSS
69.5%
top 1.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateApr 30

Description

Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

🔴Vulnerability Details

2
GHSA
GHSA-v5w3-2jf3-qqmq: Cross-site scripting vulnerability for Internet Information Server (IIS) 42022-04-30
CVEList
CVE-2002-0075: Cross-site scripting vulnerability for Internet Information Server (IIS) 42003-04-02

📋Vendor Advisories

1
Cisco
Microsoft IIS Vulnerabilities in Cisco Products - MS02-0182002-04-15