← All CVEs

CVE-2002-2073

medium · 4.3

Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.

4.3
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2002-12-31
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

VendorProductAffected versions
microsoftsite_server3.0
microsoftsite_server_commerce3.0
microsoftwindows_nt4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-2073