CVE-2000-0085

Hotmail - Stored Cross-Site Scripting via IMG Tag LOWSRC or DYNRC Parameters

Title source: llm
STIX 2.1

Description

Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-2000-0085

Scores

EPSS 0.1494
EPSS Percentile 96.4%

Details

Status published
Products (1)
microsoft/hotmail
Published Jan 04, 2000
Tracked Since Feb 18, 2026