7.5
CVSSv2

CVE-2002-0148

Published: 22/04/2002 Updated: 23/11/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote malicious users to execute arbitrary script as other users via an HTTP error page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet information server 4.0

microsoft internet information services 5.0

Vendor Advisories

This advisory describes a vulnerability that affects Cisco products and applications that are installed on Microsoft operating systems incorporating the use of the Internet Information Server (IIS), and is based on the vulnerability of IIS, not due to a defect of the Cisco product or application A number of vulnerabilities were discove ...

Exploits

source: wwwsecurityfocuscom/bid/4486/info A Cross Site Scripting issue exists in some versions of IIS The HTTP Error Page created by IIS may, under some circumstances, contain HTML content which includes unsanitized user supplied input An attacker may construct a link to a vulnerable server such that it exploits this vulnerability Whe ...