CVE-2002-1908 describes a denial-of-service vulnerability in Microsoft IIS 5.0 and 5.1, where a remote attacker can exhaust CPU resources by sending an HTTP request with an excessively long Host header containing many forward slashes. This vulnerability has a CVSS score of 5.0, indicating a medium severity, as it is network-exploitable with low attack complexity and no authentication required, leading to a partial availability impact. While no public exploit code or active exploitation is noted, and community discussion is minimal, its EPSS score suggests it's more likely to be exploited than a small percentage of other CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.