First published: Tue Dec 31 2002(Updated: )
Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1908 is classified as a denial of service vulnerability that can lead to increased CPU consumption on the server.
To mitigate CVE-2002-1908, consider upgrading to a newer version of Microsoft IIS that does not have this vulnerability.
CVE-2002-1908 specifically affects Microsoft Internet Information Services version 5.0 and 5.1.
Yes, CVE-2002-1908 can be exploited remotely through specially crafted HTTP requests.
Exploitation of CVE-2002-1908 can lead to server denial of service, causing unresponsive services and degradation of performance.