PT-2003-1442 · Microsoft · Iis

Published

2003-05-30

·

Updated

2020-11-23

·

CVE-2003-0223

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Information Server (IIS) versions 4.0 through 5.1
Description: A cross-site scripting issue exists in the ASP function responsible for redirection, allowing remote attackers to embed a URL containing script in a redirection message.
Recommendations: For Microsoft Internet Information Server (IIS) versions 4.0 through 5.1, consider disabling the ASP redirection function until a patch is available. Restrict access to the vulnerable ASP function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0223

Affected Products

Iis