{"api_version":"1","generated_at":"2026-07-23T04:29:29+00:00","cve":"CVE-2001-1325","urls":{"html":"https://cve.report/CVE-2001-1325","api":"https://cve.report/api/cve/CVE-2001-1325.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-1325","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-1325"},"summary":{"title":"CVE-2001-1325","description":"Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).","state":"PUBLISHED","assigner":"mitre","published_at":"2001-04-20 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/3AE02004.57FDF958%40guninski.com","name":"http://www.securityfocus.com/archive/1/3AE02004.57FDF958%40guninski.com","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6448","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6448","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/2633","name":"http://www.securityfocus.com/bid/2633","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Microsoft IE and OE XML Stylesheets Active Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/3AE02004.57FDF958@guninski.com","name":"BUGTRAQ:20010420 XML scripting in IE, Outlook Express","refsource":"MITRE","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"504"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-1325","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-1325","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"1325","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"1325","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"1325","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"outlook_express","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"1325","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"outlook_express","cpe6":"5.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:51:07.968Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ie-xml-stylesheets-scripting(6448)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6448"},{"name":"2633","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/2633"},{"name":"20010420 XML scripting in IE, Outlook Express","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/3AE02004.57FDF958%40guninski.com"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-04-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-18T21:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ie-xml-stylesheets-scripting(6448)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6448"},{"name":"2633","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/2633"},{"name":"20010420 XML scripting in IE, Outlook Express","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/3AE02004.57FDF958%40guninski.com"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-1325","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ie-xml-stylesheets-scripting(6448)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6448"},{"name":"2633","refsource":"BID","url":"http://www.securityfocus.com/bid/2633"},{"name":"20010420 XML scripting in IE, Outlook Express","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/3AE02004.57FDF958@guninski.com"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-1325","datePublished":"2002-05-03T04:00:00.000Z","dateReserved":"2002-05-01T00:00:00.000Z","dateUpdated":"2024-08-08T04:51:07.968Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-04-20 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*","matchCriteriaId":"E6B8985B-B927-4928-B1DB-18E29F796992"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*","matchCriteriaId":"40F8042F-C621-45AE-9F8C-70469579643A"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:outlook_express:5.0:*:*:*:*:*:*:*","matchCriteriaId":"1F71D6D7-6CB2-4BE9-839A-A5714144029C"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:outlook_express:5.5:*:*:*:*:*:*:*","matchCriteriaId":"57C8ACA2-A3C6-4435-9C0C-B316879FE1FA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"1325","Ordinal":"1","Title":"CVE-2001-1325","CVE":"CVE-2001-1325","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"1325","Ordinal":"1","NoteData":"Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).","Type":"Description","Title":"CVE-2001-1325"},{"CveYear":"2001","CveId":"1325","Ordinal":"2","NoteData":"2002-05-03","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"1325","Ordinal":"3","NoteData":"2017-12-18","Type":"Other","Title":"Modified"}]}}}