5
CVSSv2

CVE-2000-0653

Published: 20/07/2000 Updated: 12/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Microsoft Outlook Express allows remote malicious users to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft outlook express 4.0

microsoft outlook express 4.01

microsoft outlook express 5.0

microsoft outlook express 5.0.1

Exploits

source: wwwsecurityfocuscom/bid/962/info Microsoft Outlook Express 5, and possibly other email clients that parse HTML messages, can be made to run Active Scripting that will read any new messages that arrive after the hostile code has been run Example code: <SCRIPT> a=windowopen("about:<A HREF='javascript:alert(xbodyinnerT ...