peter bassill · operator
$ cve CVE-2002-0148 JSON

CVE-2002-0148 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 64.5% (pctl 99)

Patch early

A public exploit exists.

Description

Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS64.49% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2002-04-22
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftinternet information server
microsoftinternet information services

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD