← back
CVE-2002-1744

CVE-2002-1744

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 65%
from disclosure to weapon0 days
Published on NVDJun 21
1st PoCApr 16
exploitation probability
65%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.