Back
CVE-2002-2073
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| microsoft | site_server | 3.0 |
| microsoft | site_server_commerce | 3.0 |
| microsoft | windows_nt | 4.0 |
GitHub Security Advisory GHSA-33j6-jcch-j278
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on...
References (6)
- http://marc.info/?l=vulnwatch&m=101235440104716&w=2
- http://www.iss.net/security_center/static/8050.php
- http://www.securityfocus.com/bid/3999 Exploit, Vendor Advisory
- http://marc.info/?l=vulnwatch&m=101235440104716&w=2
- http://www.iss.net/security_center/static/8050.php
- http://www.securityfocus.com/bid/3999 Exploit, Vendor Advisory
Risk Scores
CVSS Score
4.3 / 10
EPSS Score
12.86%
Top 4% most likely to be exploited
Threat Score
21.1 / 100
Data Sources
NVD
EPSS
GitHub