Vulnerability Name: | CVE-2000-0746 (CCN-5156) | ||||||||
Assigned: | 2000-08-25 | ||||||||
Published: | 2000-08-25 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Aug 21 2000 - 08:17:10 CDT IIS 5.0 cross site scripting vulnerability - using .shtml files or /_vti_bin/shtml.dll Source: MITRE Type: CNA CVE-2000-0746 Source: MITRE Type: CNA CVE-2000-1104 Source: CCN Type: CERT Advisory CA-2000-02 Malicious HTML Tags Embedded in Client Web Requests Source: CCN Type: Microsoft Security Bulletin MS00-060 FAQ Microsoft Security Bulletin (MS00-060):Frequently Asked Questions Source: CCN Type: Microsoft Security Bulletin MS00-060 Patch Available for "IIS Cross-Site Scripting" Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS01-041 Malformed RPC Request Can Cause Service Failure Source: CCN Type: Microsoft Security Bulletin MS02-001 Trusting Domains Do Not Verify Domain Membership of SIDs in Authorization Data Source: CCN Type: Microsoft Security Bulletin MS02-062 Cumulative Patch for Internet Information Service (Q327696) Source: CCN Type: Microsoft Security Bulletin MS03-018 Cumulative Patch for Internet Information Service (811114) Source: CCN Type: OSVDB ID: 9199 Microsoft IIS shtml.dll XSS Source: CCN Type: OSVDB ID: 9200 Microsoft IIS Unspecified XSS Variant Source: BID Type: Patch, Vendor Advisory 1594 Source: CCN Type: BID-1594 Microsoft FrontPage/IIS Cross Site Scripting shtml.dll Vulnerability Source: BID Type: Patch, Vendor Advisory 1595 Source: CCN Type: BID-1595 Microsoft IIS Cross Site Scripting .shtml Vulnerability Source: BUGTRAQ Type: UNKNOWN 20000821 IIS 5.0 cross site scripting vulnerability - using .shtml files or /_vti_bin/shtml.dll Source: MS Type: UNKNOWN MS00-060 Source: XF Type: UNKNOWN iis-cross-site-scripting(5156) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |