CVE-2003-0009

Microsoft Windows ME - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by s0h · cremotewindows
https://www.exploit-db.com/exploits/22289

Scores

EPSS 0.1808
EPSS Percentile 95.2%

Details

Status published
Products (2)
microsoft/windows_me
microsoft/windows_xp (2 CPE variants)
Published Mar 07, 2003
Tracked Since Feb 18, 2026