5
CVSSv2

CVE-2000-0105

Published: 01/02/2000 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Outlook Express 5.01 and Internet Explorer 5.01 allow remote malicious users to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft outlook express 5.0

Exploits

source: wwwsecurityfocuscom/bid/962/info Microsoft Outlook Express 5, and possibly other email clients that parse HTML messages, can be made to run Active Scripting that will read any new messages that arrive after the hostile code has been run Example code: <SCRIPT> a=windowopen("about:<A HREF='javascript:alert(xbodyinnerT ...