Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files.
                
            References
                    | Link | Resource | 
|---|---|
| http://online.securityfocus.com/archive/1/268303 | Broken Link Third Party Advisory VDB Entry | 
| http://www.securityfocus.com/bid/4543 | Broken Link Third Party Advisory VDB Entry | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/8853 | Third Party Advisory VDB Entry | 
| http://online.securityfocus.com/archive/1/268303 | Broken Link Third Party Advisory VDB Entry | 
| http://www.securityfocus.com/bid/4543 | Broken Link Third Party Advisory VDB Entry | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/8853 | Third Party Advisory VDB Entry | 
Configurations
                    History
                    No history.
Information
                Published : 2002-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2002-1745
Mitre link : CVE-2002-1745
CVE.ORG link : CVE-2002-1745
JSON object : View
Products Affected
                microsoft
- internet_information_services
CWE
                
                    
                        
                        CWE-193
                        
            Off-by-one Error
