Vulnerabilities > CVE-2002-0075 - Unspecified vulnerability in Microsoft products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft

Summary

Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.

Vulnerable Configurations

Part Description Count
Application
Microsoft
2

Oval

  • accepted2010-12-20T04:00:40.972-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameShane Shaffer
      organizationG2, Inc.
    • nameJosh Turpin
      organizationSymantec Corporation
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionCross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.
    familywindows
    idoval:org.mitre.oval:def:210
    statusdeprecated
    submitted2003-10-10T12:00:00.000-04:00
    titleDEPRECATED: Windows 2000 IIS HTTP Redirect Error Message Cross-site Scripting
    version32
  • classvulnerability
    contributors
    • nameTiffany Bergeron
      organizationThe MITRE Corporation
    • nameJosh Turpin
      organizationSymantec Corporation
    descriptionCross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.
    familywindows
    idoval:org.mitre.oval:def:58
    statusdeprecated
    submitted2003-08-20T12:00:00.000-04:00
    titleDEPRECATED: Windows NT IIS HTTP Redirect Error Message Cross-site Scripting
    version28