5.1
CVSSv2

CVE-2000-0942

Published: 19/12/2000 Updated: 12/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote malicious users to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft indexing service

Exploits

source: wwwsecurityfocuscom/bid/1861/info A cross-site scripting vulnerability has been reported in Microsoft Indexing Services for Windows 2000/NT4 and its handling of the htw extension If a user inadvertantly opened a hostile link through a browser or HTML compliant e-mail client, active content such as JavaScript may be executed For ...