CVE

Id
1663  
CVE No.
CVE-2000-0085  
Status
Candidate  
Description
Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.  
Phase
Proposed (20000125)  
Votes
ACCEPT(1) Baker | MODIFY(1) Frech  
Comments
Frech> XF:hotmail-java-execute