CVE-2000-0942
Microsoft Indexing Service - Cross-Site Scripting via CiRestriction Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-0942. PoCs published by Georgi Guninski.
AI-analyzed exploit summary This is a writeup describing a cross-site scripting (XSS) vulnerability in Microsoft Indexing Services for Windows 2000/NT4. The vulnerability allows execution of arbitrary JavaScript via a maliciously crafted URL targeting the .htw extension, which is handled by webhits.dll.
Description
The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
Exploits (1)
This is a writeup describing a cross-site scripting (XSS) vulnerability in Microsoft Indexing Services for Windows 2000/NT4. The vulnerability allows execution of arbitrary JavaScript via a maliciously crafted URL targeting the .htw extension, which is handled by webhits.dll.