5
CVSSv2

CVE-2002-1744

Published: 31/12/2002 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote malicious users to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet information services 5.0

Exploits

source: wwwsecurityfocuscom/bid/4525/info Microsoft IIS 50 ships with a sample script that may be used to view the source code of other scripts in the sample scripts (/IISSAMPLES) directory However, this script (CodeBrwsasp) does not adequately filter unicode representations of directory traversals For example, an attacker can break o ...