CVE-2002-0148

Internet Information Server 4.0-5.1 - Cross-Site Scripting via HTTP Error Page

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0148. PoCs published by Thor Larholm.

AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in IIS error pages, where unsanitized user input is reflected in the HTTP error response. The PoC constructs a malicious URL that executes arbitrary JavaScript in the context of the vulnerable site.

Description

Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Thor Larholm · textremotewindows
https://www.exploit-db.com/exploits/21372

This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in IIS error pages, where unsanitized user input is reflected in the HTTP error response. The PoC constructs a malicious URL that executes arbitrary JavaScript in the context of the vulnerable site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Information Services (IIS)
No auth needed
Prerequisites: Vulnerable IIS server · User interaction (clicking a malicious link)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8803.php
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/3339
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A81
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A92
US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2002-09.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/886699
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4486

Scores

EPSS 0.6449
EPSS Percentile 99.1%

Details

Status published
Products (2)
microsoft/internet_information_server 4.0
microsoft/internet_information_services 5.0
Published Apr 22, 2002
Tracked Since Feb 18, 2026