CVE-2000-0329
published 1999-11-11CVE-2000-0329: A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the…
PriorityP420medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EXPLOIT
EPSS
7.69%
93.9th percentile
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | ie | — | — |
| microsoft | ie | — | — |
| microsoft | ie | — | — |
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook_express | — | — |
| microsoft | outlook_express | — | — |
| microsoft | outlook_express | — | — |
| microsoft | outlook_express | — | — |
| microsoft | outlook_express | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Snitz Forums 2000 3.0/3.1/3.3 - Image Tag Cross-Agent Scripting
exploitdb·2002-02-27
CVE-2002-0329 Snitz Forums 2000 3.0/3.1/3.3 - Image Tag Cross-Agent Scripting
Snitz Forums 2000 3.0/3.1/3.3 - Image Tag Cross-Agent Scripting
---
source: https://www.securityfocus.com/bid/4192/info
Snitz Forums 2000 is ASP-based web forum software. It runs on Microsoft Windows operating systems.
Snitz Forums 2000 allows users to include images in forum messages using image tags, with the following syntax:
[img]url of image[/img]
It is possible to inject arbitrary script code into forum messages via these image tags. Script code will be executed in the browser of the user viewing the forum message, in the context of the website running the vulnerable software. This may allow an attacker to steal cookie-based authentication credentials.
[img]javasCript:alert('Hello world.')[/img]
Exploit-DB
Microsoft Internet Explorer 4.x/5 / Outlook 2000 0/98 0/Express 4.x - ActiveX '.CAB' File Execution
exploitdb·1999-11-08
CVE-2000-0329 Microsoft Internet Explorer 4.x/5 / Outlook 2000 0/98 0/Express 4.x - ActiveX '.CAB' File Execution
Microsoft Internet Explorer 4.x/5 / Outlook 2000 0/98 0/Express 4.x - ActiveX '.CAB' File Execution
---
Microsoft Internet Explorer 4.0 for Windows 95/Windows NT 4,Internet Explorer 4.1 for Windows 95/Windows 98/Windows NT 4,Internet Explorer 5.0 for Windows 2000/Windows 95/Windows 98/Windows NT 4,Internet Explorer 4.0.1 for Windows 98/Windows NT 4.0,Outlook 2000 0/98 0,Outlook Express 4.27.3110/4.72.2106/4.72.3120/4.72.3612 ActiveX CAB File Execution Vulnerability
source: https://www.securityfocus.com/bid/775/info
Introduction
Microsoft's Active Setup Control (asctrls.ocx) shipped with Internet Explorer 4 and above has a vulnerability in it as discovered by Juan Carlos Garcia Cuartango , which was posted on BUGTRAQ (ID 775) in the month of November, 1999. Microsoft has released patch
No writeups or analysis indexed.
1999-11-11
Published