CVE-2003-0002

Microsoft Content Management Server 2001 - Cross-Site Scripting via ManualLogin.asp REASONTXT Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0002. PoCs published by overclocking_a_la_abuela.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Microsoft Content Management Server 2001. The PoC constructs a malicious URL that injects arbitrary JavaScript code, which executes in the context of the vulnerable site when visited by a user.

Description

Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by overclocking_a_la_abuela · textwebappsasp
https://www.exploit-db.com/exploits/21920

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Microsoft Content Management Server 2001. The PoC constructs a malicious URL that injects arbitrary JavaScript code, which executes in the context of the vulnerable site when visited by a user.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Content Management Server 2001
No auth needed
Prerequisites: A vulnerable instance of Microsoft Content Management Server 2001 · A user to click on the malicious link
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5922
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103417794800719&w=2
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10318.php

Scores

EPSS 0.2333
EPSS Percentile 97.5%

Details

Status published
Products (1)
microsoft/content_management_server 2001 (2 CPE variants)
Published Feb 07, 2003
Tracked Since Feb 18, 2026