VDB
CVE-2002-0071
CVE-2002-0071
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.
EPSS 33.64% · 98.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
33.64%
98.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | internet_information_server | 4.0 |
| microsoft | internet_information_services | 5.0 |
| n/a | n/a | * |
Timeline
- CVE Published
- Sep 23, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 11, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
References
- 4474 vdb
- MS02-018 vendor-advisory
- oval:org.mitre.oval:def:45 vdb
- 20020411 KPMG-2002010: Microsoft IIS .htr ISAPI buffer overrun mailing-list
- VU#363715 third-party-advisory
- iis-htr-isapi-bo(8799) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2002-0071 advisory
- http://www.atstake.com/research/advisories/2002/a041002-1.txt technical
- http://www.cert.org/advisories/CA-2002-09.html advisory
- http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml technical
- http://www.osvdb.org/3325 technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A130 technical