PT-2000-1854 · Microsoft · Indexing Services

Published

2000-12-19

·

Updated

2018-10-12

·

CVE-2000-0942

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Indexing Services for Windows 2000
Description The issue allows remote attackers to conduct a cross-site scripting attack via a CiRestriction parameter in a .htw request.
Recommendations For Microsoft Indexing Services for Windows 2000, consider restricting access to the CiWebHitsFile component until a patch is available. As a temporary workaround, avoid using the CiRestriction parameter in .htw requests to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0942

Affected Products

Indexing Services