VYPR
Unrated severityNVD Advisory· Published Jan 9, 2001· Updated Apr 16, 2026

CVE-2000-1104

CVE-2000-1104

Description

Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A variant of the IIS cross-site scripting vulnerability allows script injection via error messages, affecting IIS 4.0 and 5.0.

Vulnerability

A variant of the cross-site scripting vulnerability originally discussed in Microsoft Security Bulletin MS00-060 (CVE-2000-0746) affects Microsoft Internet Information Server (IIS) versions 4.0 and 5.0. The vulnerability occurs when a malicious web site operator embeds scripts in a link to a trusted site, and the server returns the unquoted script in an error message, which then executes in the client's browser within the trusted site's context [1].

Exploitation

An attacker needs to lure a user to click on a specially crafted link that points to a trusted IIS web server. The server processes the request and generates an error message containing the malicious script without proper quoting, causing the browser to execute the script in the security context of the trusted site. No authentication or special privileges are required beyond the ability to craft a link and convince a user to click it [1].

Impact

Successful exploitation allows the attacker to execute arbitrary scripts in the user's browser within the security context of the trusted web site. This can lead to disclosure of sensitive data, session hijacking, or other malicious actions that the trusted site's scripts could perform. The impact is the same as the original cross-site scripting vulnerability [1].

Mitigation

Microsoft released an updated patch in November 2000 that eliminates all known variants of the vulnerability, including CVE-2000-1104. Customers who applied the original version of the patch should apply the new version to ensure full protection. The affected software includes IIS 4.0 and IIS 5.0. No workaround is documented; applying the patch is the recommended mitigation [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.