The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2002-1769
http://www.securityfocus.com/bid/5213