CVE-2002-0419

N/A Unknown
Published: August 12, 2002 Modified: April 16, 2026
View on NVD

Description

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.iss.net/security_center/static/8382.php
Source: cve@mitre.org
Vendor Advisory
http://www.securityfocus.com/bid/4235
Source: cve@mitre.org
Exploit Vendor Advisory
http://marc.info/?l=bugtraq&m=101535399100534&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.iss.net/security_center/static/8382.php
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/bid/4235
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Vendor Advisory

6 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
31.3%
97th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

microsoft