CVE-2002-1973
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.
- Affected products
- Http Server, Mfc, Visual C++
- Microsoft Foundation Class Library
- = 7.0
- Working Resources Inc. Badblue
- = personal_1.7.3
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 40.0% (98th percentile)
- NVD status
- Modified
- Published
- 2005-06-28
CVE-2002-1973 at NVD
1 known exploit for CVE-2002-1973
Proof-of-concept code and exploit modules indexed by Sploitus