PT-2001-1143 · Microsoft · Iis

Published

2001-01-09

·

Updated

2018-10-30

·

CVE-2000-1104

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IIS (affected versions not specified)
Description A variant of the IIS Cross-Site Scripting issue allows a malicious web site operator to embed scripts in a link to a trusted site. These scripts are returned without quoting in an error message back to the client, which then executes them in the same context as the trusted site.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1104

Affected Products

Iis