CVE

Id
1659  
CVE No.
CVE-2000-0081  
Status
Candidate  
Description
Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.  
Phase
Proposed (20000125)  
Votes
MODIFY(1) Frech | REJECT(1) Baker  
Comments
CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:hotmail-vascript-java-injection