Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files.
References
Link | Resource |
---|---|
http://online.securityfocus.com/archive/1/268303 | Broken Link Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/4543 | Broken Link Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8853 | Third Party Advisory VDB Entry |
http://online.securityfocus.com/archive/1/268303 | Broken Link Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/4543 | Broken Link Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8853 | Third Party Advisory VDB Entry |
Configurations
History
20 Nov 2024, 23:42
Type | Values Removed | Values Added |
---|---|---|
References | () http://online.securityfocus.com/archive/1/268303 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/4543 - Broken Link, Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/8853 - Third Party Advisory, VDB Entry |
15 Feb 2024, 21:28
Type | Values Removed | Values Added |
---|---|---|
References | (BID) http://www.securityfocus.com/bid/4543 - Broken Link, Third Party Advisory, VDB Entry | |
References | (BUGTRAQ) http://online.securityfocus.com/archive/1/268303 - Broken Link, Third Party Advisory, VDB Entry | |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/8853 - Third Party Advisory, VDB Entry | |
CWE | CWE-193 | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.5 |
Information
Published : 2002-12-31 05:00
Updated : 2024-11-20 23:42
NVD link : CVE-2002-1745
Mitre link : CVE-2002-1745
CVE.ORG link : CVE-2002-1745
JSON object : View
Products Affected
microsoft
- internet_information_services
CWE
CWE-193
Off-by-one Error