CVE-2002-0736
Status: ModifiedHigh (10)—
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Base score: 10
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 32%
- Percentile among all scored CVEs: 98
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0208.html
- http://support.microsoft.com/support/kb/articles/q316/8/38.asp
- http://www.iss.net/security_center/static/8862.php
- http://www.securityfocus.com/bid/4528
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0208.html
- http://support.microsoft.com/support/kb/articles/q316/8/38.asp
- http://www.iss.net/security_center/static/8862.php
- http://www.securityfocus.com/bid/4528
Raw JSON (NVD)
Show
{
"id": "CVE-2002-0736",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-08-12T04:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-04/0208.html",
"source": "cve@mitre.org"
},
{
"url": "http://support.microsoft.com/support/kb/articles/q316/8/38.asp",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/8862.php",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/4528",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-04/0208.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.microsoft.com/support/kb/articles/q316/8/38.asp",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/8862.php",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/4528",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank."
},
{
"lang": "es",
"value": "Microsoft BackOffice 4.0 and 4.5, cuando se configura para ser accesible por otros sistemas, permite a los atacantes remotos saltarse la autenticación y acceder a las páginas administrativas ASP por medio de una petición HTTP con un tipo de autorización (auth_type) que no está en blanco."
}
],
"lastModified": "2026-06-16T21:58:02.330",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:backoffice:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60EAD9D1-B3E1-4DE3-9FCE-CBC2BC025561"
},
{
"criteria": "cpe:2.3:a:microsoft:backoffice:4.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6B7299F-C779-4E04-AA33-F91467A9EC37"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}