CVE
- Id
- 1659
- CVE No.
- CVE-2000-0081
- Status
- Candidate
- Description
- Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.
- Phase
- Proposed (20000125)
- Votes
- MODIFY(1) Frech | REJECT(1) Baker
- Comments
- CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:hotmail-vascript-java-injection