← All CVEs

CVE-2002-1745

high · 7.5

Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files.

7.5
CVSS
17.7%
EPSS (exploit prob.)
97th
EPSS percentile
2002-12-31
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-193

Affected products

VendorProductAffected versions
microsoftinternet_information_services5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-1745