CVE-2001-1325
Last modified
CVE-2001-1325 is a vulnerability of currently unknown severity. Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).. EPSS estimates a 27.29% chance of exploitation in the next 30 days.
Description
Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Explorer | 5.0 |
| Microsoft | Internet Explorer | 5.5 |
| Microsoft | Outlook Express | 5.0 |
| Microsoft | Outlook Express | 5.5 |
References
- http://www.securityfocus.com/bid/2633Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/2633Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1325?
How severe is CVE-2001-1325?
How do I fix CVE-2001-1325?
Are you affected by CVE-2001-1325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
