PT-2003-1442 · Microsoft · Iis
Published
2003-05-30
·
Updated
2020-11-23
·
CVE-2003-0223
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Internet Information Server (IIS) versions 4.0 through 5.1
Description:
A cross-site scripting issue exists in the ASP function responsible for redirection, allowing remote attackers to embed a URL containing script in a redirection message.
Recommendations:
For Microsoft Internet Information Server (IIS) versions 4.0 through 5.1, consider disabling the ASP redirection function until a patch is available. Restrict access to the vulnerable ASP function to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iis