Back

CVE-2002-2062

Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.

Published: Dec 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-f94v-48pw-mw72

Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 13.34%

Top 4% most likely to be exploited

Threat Score 21.2 / 100

Data Sources

NVD EPSS GitHub