Vulnerability
CVE-2002-1908
MEDIUM 5.0
CVE-2002-1908 is a medium-severity vulnerability (CVSS v2 5.0). As of 2026-10-09, 371 hosts in our data show software it affects on an open service in at least 15 countries.
Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.
- Published
- 2002-12-31
- Last modified
- 2026-06-16
- CVSS score
- 5.0 CVSS v2
- CVSS vector (v2)
- AV:N/AC:L/Au:N/C:N/I:N/A:P
- Exploit likelihood (EPSS)
- 13.7% in the next 30 days (top 4% of CVEs)
Exposure in our data
371 hosts
Hosts whose banner shows an affected software version on a service open at their latest check.
Not counted: 1 host with this CVE only from an older observation.
4 more hosts had it earlier (the software version has since changed or the service is gone).
Counted 2026-10-09 08:20 UTC
By country
| United States US | 109 |
| South Korea KR | 84 |
| Spain ES | 30 |
| Italy IT | 28 |
| Germany DE | 17 |
| Taiwan TW | 16 |
| Sweden SE | 12 |
| Japan JP | 10 |
| Austria AT | 6 |
| Russia RU | 6 |
| Bulgaria BG | 5 |
| Poland PL | 5 |
| Switzerland CH | 4 |
| United Kingdom GB | 4 |
| Netherlands NL | 4 |
Affected software seen
| internet_information_services 5.0 | 371 |