Back
CVE-2002-2062
Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 6.0 |
GitHub Security Advisory GHSA-f94v-48pw-mw72
Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when...
References (8)
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0037.html Exploit, Vendor Advisory
- http://www.geocities.co.jp/SiliconValley/1667/advisory02e.html Exploit, Vendor Advisory
- http://www.iss.net/security_center/static/9290.php
- http://www.securityfocus.com/bid/4954 Exploit
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0037.html Exploit, Vendor Advisory
- http://www.geocities.co.jp/SiliconValley/1667/advisory02e.html Exploit, Vendor Advisory
- http://www.iss.net/security_center/static/9290.php
- http://www.securityfocus.com/bid/4954 Exploit
Risk Scores
CVSS Score
4.3 / 10
EPSS Score
13.34%
Top 4% most likely to be exploited
Threat Score
21.2 / 100
Data Sources
NVD
EPSS
GitHub