CVE-2001-0902: High severity Microsoft Internet Information Services vulnerability
Published Nov 20, 2001
·Updated
Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.
Affected Software
1 affected component
Microsoft Internet Information Services=5.0
Event History
Nov 20, 2001
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0902?
CVE-2001-0902 is considered a moderate severity vulnerability.
2
How do I fix CVE-2001-0902?
To fix CVE-2001-0902, you should upgrade to a later version of Microsoft IIS that does not have this vulnerability.
3
Which version of Microsoft IIS is affected by CVE-2001-0902?
CVE-2001-0902 specifically affects Microsoft Internet Information Services version 5.0.
4
What impact does CVE-2001-0902 have on web servers?
CVE-2001-0902 allows remote attackers to spoof web log entries, which can lead to confusion in auditing and monitoring.
5
Is there a workaround for CVE-2001-0902?
A potential workaround is to implement monitoring of HTTP requests for hex-encoded newline or form-feed characters.