CVE-2000-0746
Microsoft FrontPage - Cross-Site Scripting via Error Message
Title source: llmDescription
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.
References (4)
Core 4
Core References
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1594
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1595
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-060
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=39A12BD6.E811BF4F%40nat.bg
Scores
EPSS
0.0948
EPSS Percentile
95.0%
Details
Status
published
Products (3)
microsoft/frontpage
microsoft/internet_information_server
4.0
microsoft/internet_information_services
5.0
Published
Oct 20, 2000
Tracked Since
Feb 18, 2026