CVE-2000-0746
published 2000-10-20CVE-2000-0746: Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed…
PriorityP422high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
8.04%
94.1th percentile
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_information_server | — | — |
| microsoft | internet_information_services | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-68vx-xw79-w5cg: Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to
ghsa_unreviewed·2022-04-30·CVSS 7.5
CVE-2000-1104 [HIGH] GHSA-68vx-xw79-w5cg: Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.
GHSA
GHSA-93vc-c3w9-g6c9: Vulnerabilities in IIS 4
ghsa_unreviewed·2022-04-30
CVE-2000-0746 [HIGH] GHSA-93vc-c3w9-g6c9: Vulnerabilities in IIS 4
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.
No detection rules found.
Exploit-DB
iPlanet 4.1 Web Publisher - Remote Buffer Overflow (1)
exploitdb·2001-05-15
CVE-2001-0746 iPlanet 4.1 Web Publisher - Remote Buffer Overflow (1)
iPlanet 4.1 Web Publisher - Remote Buffer Overflow (1)
---
source: https://www.securityfocus.com/bid/2732/info
iPlanet Webserver is an http server product offered by the Sun-Netscape Alliance.
By sending a specially crafted request (composed of at least 2000 characters) it is possible to cause a buffer overflow. This could cause the termination of the affected service, requiring a restart and enabling a remote attacker to effect a denial of service attack.
If the submitted buffer is properly structured, it may yield a remote system shell.
Successful exploitation of this vulnerability could lead to a complete compromise of the host.
Note that while only installations of iWS4.1sp3-7 on Windows NT are immediately vulnerable to this attack, all users of iWS4.1sp3-7 are advised to instal
Exploit-DB
iPlanet 4.1 Web Publisher - Remote Buffer Overflow (2)
exploitdb·2001-05-15
CVE-2001-0746 iPlanet 4.1 Web Publisher - Remote Buffer Overflow (2)
iPlanet 4.1 Web Publisher - Remote Buffer Overflow (2)
---
source: https://www.securityfocus.com/bid/2732/info
iPlanet Webserver is an http server product offered by the Sun-Netscape Alliance.
By sending a specially crafted request (composed of at least 2000 characters) it is possible to cause a buffer overflow. This could cause the termination of the affected service, requiring a restart and enabling a remote attacker to effect a denial of service attack.
If the submitted buffer is properly structured, it may yield a remote system shell.
Successful exploitation of this vulnerability could lead to a complete compromise of the host.
Note that while only installations of iWS4.1sp3-7 on Windows NT are immediately vulnerable to this attack, all users of iWS4.1sp3-7 are advised to instal
No writeups or analysis indexed.
http://www.securityfocus.com/bid/1594http://www.securityfocus.com/bid/1595http://www.securityfocus.com/templates/archive.pike?list=1&msg=39A12BD6.E811BF4F%40nat.bghttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-060http://www.securityfocus.com/bid/1594http://www.securityfocus.com/bid/1595http://www.securityfocus.com/templates/archive.pike?list=1&msg=39A12BD6.E811BF4F%40nat.bghttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-060
2000-10-20
Published