Vulnerability

CVE-2002-1908

MEDIUM 5.0

CVE-2002-1908 is a medium-severity vulnerability (CVSS v2 5.0). As of 2026-10-09, 371 hosts in our data show software it affects on an open service in at least 15 countries.

Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.

Published
2002-12-31
Last modified
2026-06-16
CVSS score
5.0 CVSS v2
CVSS vector (v2)
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploit likelihood (EPSS)
13.7% in the next 30 days (top 4% of CVEs)

Exposure in our data

371 hosts

Hosts whose banner shows an affected software version on a service open at their latest check.

Not counted: 1 host with this CVE only from an older observation.

4 more hosts had it earlier (the software version has since changed or the service is gone).

Counted 2026-10-09 08:20 UTC

By country

United States US109
South Korea KR84
Spain ES30
Italy IT28
Germany DE17
Taiwan TW16
Sweden SE12
Japan JP10
Austria AT6
Russia RU6
Bulgaria BG5
Poland PL5
Switzerland CH4
United Kingdom GB4
Netherlands NL4

Affected software seen

internet_information_services 5.0371