CVE-2003-0526
Summary
| CVE | CVE-2003-0526 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-08-18 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found." |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Isa Server | 2000 | All | All | All |
| Application | Microsoft | Isa Server | 2000 | fp1 | All | All |
| Application | Microsoft | Isa Server | 2000 | sp1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Neohapsis Archives - VulnWatch - #0031 - [VulnWatch] Microsoft ISA Server HTTP error handler XSS (TL#007) | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| { PivX Solutions, LLC } | af854a3a-2127-422b-91ae-364da2661108 | pivx.com | |
| Microsoft Security Bulletin MS03-028 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Neohapsis Archives - VulnWatch - #0029 - [VulnWatch] ISA Server - Error Page Cross Site Scripting | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Vendor Advisory |
| 'Microsoft ISA Server HTTP error handler XSS (TL#007)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| 'Microsoft ISA Server HTTP error handler XSS (TL#007)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'ISA Server - Error Page Cross Site Scripting' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.