Vulnerability Name: | CVE-2000-1105 (CCN-5502) | ||||||||
Assigned: | 2000-11-10 | ||||||||
Published: | 2000-11-10 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Nov 10 2000 - 11:23:22 CST IE 5.x Win2000 Indexing service vulnerability Source: WIN2KSEC Type: Exploit, Patch, Vendor Advisory 20001110 IE 5.x Win2000 Indexing service vulnerability Source: MITRE Type: CNA CVE-2000-1105 Source: CCN Type: US-CERT VU#829845 Microsoft Windows 2000 Indexing Services enumerates local file locations via ixsso.query ActiveX object Source: CCN Type: Microsoft Security Bulletin MS00-098 Patch Available for 'Indexing Service File Enumeration' Vulnerability Source: CCN Type: OSVDB ID: 10979 ixsso.query ActiveX Object Arbitrary File Existence Verification Source: BUGTRAQ Type: UNKNOWN 20001110 IE 5.x Win2000 Indexing service vulnerability Source: BID Type: Exploit, Patch, Vendor Advisory 1933 Source: CCN Type: BID-1933 Microsoft Indexing Services for Windows 2000 File Verification Vulnerability Source: XF Type: UNKNOWN win2k-index-service-ixsso(5502) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |