Back

CVE-2002-1180

A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."

Published: Nov 12, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
microsoft internet_information_services 5.0

GitHub Security Advisory GHSA-89mg-cv67-4w52

A typographical error in the script source access permissions for Internet Information Server ...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 8.97%

Top 5% most likely to be exploited

Threat Score 32.7 / 100

Data Sources

NVD EPSS GitHub