Back

CVE-2002-2073

Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.

Published: Dec 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
microsoft site_server 3.0
microsoft site_server_commerce 3.0
microsoft windows_nt 4.0

GitHub Security Advisory GHSA-33j6-jcch-j278

Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 12.86%

Top 4% most likely to be exploited

Threat Score 21.1 / 100

Data Sources

NVD EPSS GitHub