Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2002-0148

5 documents5 sources
Severity
7.5HIGH
EPSS
74.2%
top 1.16%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 22
Latest updateApr 30

Description

Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

🔴Vulnerability Details

2
GHSA
GHSA-qwp9-6j3h-v26x: Cross-site scripting vulnerability in Internet Information Server (IIS) 42022-04-30
CVEList
CVE-2002-0148: Cross-site scripting vulnerability in Internet Information Server (IIS) 42003-04-02

💥Exploits & PoCs

1
Exploit-DB
Microsoft IIS 4.0/5.0 - HTTP Error Page Cross-Site Scripting2002-04-10

📋Vendor Advisories

1
Cisco
Microsoft IIS Vulnerabilities in Cisco Products - MS02-0182002-04-15