CVE-2002-0071

Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.

Scoring

CVSS base score
2.78
EPSS probability
69.49%
Published
2003-04-02
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs