CVE-2004-1133
Microsoft w3who.dll - Cross-Site Scripting via HTTP Headers or Invalid Parameters
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web script via (1) HTTP headers such as "Connection" or (2) invalid parameters whose values are echoed in the resulting error message.
References (3)
Core 3
Core References
Various Sources x_refsource_misc
http://www.exaprobe.com/labs/advisories/esa-2004-1206.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18375
Mailing List mailing-list
x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=110234486823233&w=2
Scores
EPSS
0.0981
EPSS Percentile
95.1%
Details
Status
published
Products (1)
microsoft/w3who.dll
Published
Jan 10, 2005
Tracked Since
Feb 18, 2026