PT-2002-2466 · Microsoft · Iis

Published

2002-12-31

·

Updated

2018-10-30

·

CVE-2002-1744

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft IIS version 5.0
Description A directory traversal issue exists, allowing remote attackers to view source code and determine the existence of arbitrary files. This is achieved by using a hex-encoded string, %c0%ae%c0%ae, which represents the Unicode for ".." (dot dot).
Recommendations For Microsoft IIS version 5.0, update to a newer version to mitigate the risk, or as a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1744

Affected Products

Iis