cbcvebase.
CVE-2002-0147
published 2002-04-22

CVE-2002-0147: Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service…

PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
52.16%
98.8th percentile
Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoproducts_ms02-018
microsoftinternet_information_server
microsoftinternet_information_services

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability targets ASP data transfer mechanism (chunked encoding) in IIS 4.0, 5.0, and 5.1 — monitor for malformed/oversized chunked-encoding HTTP requests to IIS servers running ASP
  • Affected Cisco products installed on Microsoft OS using IIS should be reviewed; exploitation is via the underlying IIS vulnerability, not the Cisco application itself
  • ·Vulnerability is present in IIS versions 4.0, 5.0, and 5.1 specifically; scope detection/patching efforts to these versions
  • ·Multiple vulnerabilities were bundled under MS02-018; CVE-2002-0147 is specifically the 'Microsoft-discovered variant of Chunked Encoding buffer overrun' — ensure patching targets this specific variant
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.