Vulnerability Description
Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Information Services | 5.0 |
Related Weaknesses (CWE)
References
- http://online.securityfocus.com/archive/1/268303Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/4543Broken LinkThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8853Third Party AdvisoryVDB Entry
- http://online.securityfocus.com/archive/1/268303Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/4543Broken LinkThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8853Third Party AdvisoryVDB Entry
FAQ
What is CVE-2002-1745?
CVE-2002-1745 is a vulnerability with a CVSS score of 7.5 (HIGH). Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, ...
How severe is CVE-2002-1745?
CVE-2002-1745 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1745?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Internet Information Services.