CVE-2000-1104

4 documents4 sources
Severity
7.5HIGH
EPSS
12.8%
top 5.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateApr 30

Description

Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

🔴Vulnerability Details

2
GHSA
GHSA-68vx-xw79-w5cg: Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to2022-04-30
CVEList
CVE-2000-1104: Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to2000-12-19

💥Exploits & PoCs

1
Exploit-DB
CNC Technology BizDB 1.0 - 'bizdb-search.cgi' Remote Command Execution2000-04-13