Vulnerabilities > CVE-2000-0746 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | CGI abuses : XSS |
NASL id | FRONTPAGE_XSS.NASL |
description | The version of the FrontPage extensions running on the remote web server is affected by a cross-site scripting (XSS) vulnerability in shtml.dll due to improper validation of filenames. An unauthenticated, remote attacker can exploit this, by convincing a user to follow a specially crafted URL, to execute arbitrary script code in the user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11395 |
published | 2003-03-15 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11395 |
title | Microsoft IIS shtml.dll XSS |
code |
|
References
- http://www.securityfocus.com/bid/1594
- http://www.securityfocus.com/bid/1594
- http://www.securityfocus.com/bid/1595
- http://www.securityfocus.com/bid/1595
- http://www.securityfocus.com/templates/archive.pike?list=1&msg=39A12BD6.E811BF4F%40nat.bg
- http://www.securityfocus.com/templates/archive.pike?list=1&msg=39A12BD6.E811BF4F%40nat.bg
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-060
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-060