CVE
- Id
- 730
- CVE No.
- CVE-1999-0750
- Status
- Candidate
- Description
- Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user"s Hotmail account.
- Phase
- Proposed (19991222)
- Votes
- ACCEPT(1) Levy | MODIFY(2) Frech, Stracener | NOOP(1) Baker
- Comments
- Stracener> Many sites are vulnerable to this problem. I recommend removing the | explicit references to Hotmail and making the description more generic. | Suggest: Javascript can be injected using the STYLE tag in an HTML | formatted e-mail, allowing remote attackers to execute commands on user | accounts. | Frech> XF:hotmail-html-style-embed