CVE-2003-0702
Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information…
Does this matter?
Lower severity and a low EPSS score (2.80%). Track it; it rarely justifies an emergency change on its own.
Description
Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information Server (IIS) via a certain URL through SSL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.80% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- iss/realsecure server sensor
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=106278164225389&w=2
- http://www.enteredge.com/research/CAN-2003-0702.asp
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13088
- http://marc.info/?l=bugtraq&m=106278164225389&w=2
- http://www.enteredge.com/research/CAN-2003-0702.asp
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13088
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.