ID

VAR-200208-0012


CVE

CVE-2002-0419


TITLE

Microsoft Internet Information Services Information disclosure vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200208-053

DESCRIPTION

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server. Microsoft IIS supports Basic and NTLM authentication. When a valid authentication request is submitted for either message with an invalid username and password, an error message will be returned. This happens even if anonymous access to the requested resource is allowed. An attacker may be able to use this information to launch further intelligent attacks against the server, or to launch a brute-force password attack against a known username

Trust: 1.17

sources: NVD: CVE-2002-0419 // BID: 4235

AFFECTED PRODUCTS

vendor:microsoftmodel:internet information serverscope:eqversion:4.0

Trust: 1.6

vendor:microsoftmodel:internet information servicesscope:eqversion:5.0

Trust: 1.6

vendor:microsoftmodel:internet information serverscope:eqversion:5.0

Trust: 0.6

vendor:microsoftmodel:internet information serverscope:eqversion:5.1

Trust: 0.6

vendor:microsoftmodel:iisscope:eqversion:5.1

Trust: 0.3

vendor:microsoftmodel:iisscope:eqversion:5.0

Trust: 0.3

vendor:microsoftmodel:iis alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:iisscope:eqversion:4.0

Trust: 0.3

sources: BID: 4235 // CNNVD: CNNVD-200208-053 // NVD: CVE-2002-0419

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-0419
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200208-053
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2002-0419
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-200208-053 // NVD: CVE-2002-0419

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.0

sources: NVD: CVE-2002-0419

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200208-053

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-200208-053

EXTERNAL IDS

db:NVDid:CVE-2002-0419

Trust: 1.9

db:BIDid:4235

Trust: 1.9

db:CNNVDid:CNNVD-200208-053

Trust: 0.6

sources: BID: 4235 // CNNVD: CNNVD-200208-053 // NVD: CVE-2002-0419

REFERENCES

url:http://www.securityfocus.com/bid/4235

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=101535399100534&w=2

Trust: 1.6

url:http://www.iss.net/security_center/static/8382.php

Trust: 1.6

url:http://www.nextgenss.com/advisories/iisauth.txt

Trust: 0.3

sources: BID: 4235 // CNNVD: CNNVD-200208-053 // NVD: CVE-2002-0419

CREDITS

Published by David Litchfield (david@nextgenss.com) of Next Generation Security Software.

Trust: 0.9

sources: BID: 4235 // CNNVD: CNNVD-200208-053

SOURCES

db:BIDid:4235
db:CNNVDid:CNNVD-200208-053
db:NVDid:CVE-2002-0419

LAST UPDATE DATE

2025-04-03T22:31:47.533000+00:00


SOURCES UPDATE DATE

db:BIDid:4235date:2009-07-11T10:56:00
db:CNNVDid:CNNVD-200208-053date:2020-11-24T00:00:00
db:NVDid:CVE-2002-0419date:2025-04-03T01:03:51.193

SOURCES RELEASE DATE

db:BIDid:4235date:2002-03-05T00:00:00
db:CNNVDid:CNNVD-200208-053date:2002-08-12T00:00:00
db:NVDid:CVE-2002-0419date:2002-08-12T04:00:00