CVE-2001-0658
Microsoft ISA Server 2000 - Cross-Site Scripting via Error Message
Title source: llmDescription
Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-045
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6991
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/3198
Scores
EPSS
0.1421
EPSS Percentile
96.2%
Details
Status
published
Products (1)
microsoft/isa_server
2000
Published
Sep 20, 2001
Tracked Since
Feb 18, 2026