CVE-2000-0746

Microsoft FrontPage - Cross-Site Scripting via Error Message

Title source: llm
STIX 2.1

Description

Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.

References (4)

Core 4
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1594
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1595
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=39A12BD6.E811BF4F%40nat.bg

Scores

EPSS 0.0948
EPSS Percentile 95.0%

Details

Status published
Products (3)
microsoft/frontpage
microsoft/internet_information_server 4.0
microsoft/internet_information_services 5.0
Published Oct 20, 2000
Tracked Since Feb 18, 2026