CVE-2002-2073
medium · 4.3Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.
4.3
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2002-12-31
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | site_server | 3.0 |
| microsoft | site_server_commerce | 3.0 |
| microsoft | windows_nt | 4.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-2073