CVE-2000-0081

Hotmail - Stored Cross-Site Scripting via Hexadecimal JavaScript Protocol

Title source: llm
STIX 2.1

Description

Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-2000-0081

Scores

EPSS 0.1877
EPSS Percentile 97.0%

Details

Status published
Products (1)
microsoft/hotmail
Published Jan 10, 2000
Tracked Since Feb 18, 2026