CVE-2002-1745
high · 7.5Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files.
7.5
CVSS
17.7%
EPSS (exploit prob.)
97th
EPSS percentile
2002-12-31
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-193
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_information_services | 5.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-1745