CVE-2002-0148
published 2002-04-22CVE-2002-0148: Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
61.46%
99.1th percentile
Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | products_ms02-018 | — | — |
| microsoft | internet_information_server | — | — |
| microsoft | internet_information_services | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect XSS exploitation attempts against IIS error pages by monitoring HTTP requests where the URL userinfo component (user@ syntax) contains a script URI or external domain reference, e.g. 'http://script@<target>/NonExistentPath' pattern. ↗
- →Monitor for theft of cookie-based authentication credentials from Microsoft domains (e.g. Hotmail, Passport) as a downstream indicator of successful exploitation. ↗
- →Flag HTTP requests to IIS servers containing a non-existent path combined with a userinfo (@ symbol) in the URL, which is the attack delivery mechanism for this CVE. ↗
- ·The vulnerability is in IIS itself (versions 4.0, 5.0, 5.1), not in Cisco products; Cisco products are affected only because they are installed on Windows systems running IIS. ↗
- ·The XSS payload executes within the context of the vulnerable site's origin, meaning cookie and session data scoped to that domain are at risk. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
vendor_cisco·2002-04-15
CVE-2002-0071 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
This advisory describes a vulnerability that affects Cisco products and
applications that are installed on Microsoft operating systems incorporating
the use of the Internet Information Server (IIS), and is based on the
vulnerability of IIS, not due to a defect of the Cisco product or application.
A number of vulnerabilities were discovered that enables an attacker to
execute arbitrary code or perform a denial of service against the server. These
vulnerabilities were discovered and publicly announced by Microsoft in their
Microsoft Security Bulletin MS02-018.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020415-ms02-018.
Cisco
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
vendor_cisco
CVE-2002-0148 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
CVE-2002-0148: Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
This advisory describes a vulnerability that affects Cisco products and applications that are installed on Microsoft operating systems incorporating the use of the Internet Information Server (IIS), and is based on the vulnerability of IIS, not due to a defect of the Cisco product or application. A number of vulnerabilities were discovered that enables an attacker to execute arbitrary code or perform a denial of service against the server. These vulnerabilities were discovered and publicly announced by Microsoft in their Microsoft Security Bulletin MS02-018. This advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020415-ms02-018 .
GHSA
GHSA-qwp9-6j3h-v26x: Cross-site scripting vulnerability in Internet Information Server (IIS) 4
ghsa_unreviewed·2022-04-30
CVE-2002-0148 [HIGH] GHSA-qwp9-6j3h-v26x: Cross-site scripting vulnerability in Internet Information Server (IIS) 4
Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.
No detection rules found.
No writeups or analysis indexed.
http://www.cert.org/advisories/CA-2002-09.htmlhttp://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtmlhttp://www.iss.net/security_center/static/8803.phphttp://www.kb.cert.org/vuls/id/886699http://www.osvdb.org/3339http://www.securityfocus.com/bid/4486https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-018https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A81https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A92http://www.cert.org/advisories/CA-2002-09.htmlhttp://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtmlhttp://www.iss.net/security_center/static/8803.phphttp://www.kb.cert.org/vuls/id/886699http://www.osvdb.org/3339http://www.securityfocus.com/bid/4486https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-018https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A81https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A92
2002-04-22
Published