Back

CVE-2002-1790

The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.

Published: Dec 31, 2002 Modified: Jun 16, 2026
NVD-CWE-noinfo

CVSS Metrics

Affected Products (5)

Vendor Product Version
microsoft exchange_server 5.5
microsoft exchange_server 5.5
microsoft exchange_server 5.5
microsoft internet_information_server 4.0
microsoft internet_information_services 5.0

GitHub Security Advisory GHSA-q27r-qgw3-47hx

The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote...

References (6)

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 33.97%

Top 2% most likely to be exploited

Threat Score 30.2 / 100

Data Sources

NVD EPSS GitHub