PT-2002-1160 · Microsoft · Iis

Published

2002-04-22

·

Updated

2018-10-30

·

CVE-2002-0071

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Internet Information Server (IIS) versions 4.0 through 5.0
Description A buffer overflow issue exists in the ism.dll ISAPI extension, which implements HTR scripting. This allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.
Recommendations For IIS versions 4.0 through 5.0, consider disabling the ism.dll ISAPI extension as a temporary workaround until a patch is available. Restrict access to HTR scripting to minimize the risk of exploitation. Avoid using long variable names in HTR requests until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0071

Affected Products

Iis