CVE-2003-0526
Estado: ModificadaMedia (6.8)—
Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 22%
- Percentil entre todas las CVEs puntuadas: 98
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0029.html
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0031.html
- http://marc.info/?l=bugtraq&m=105838519729525&w=2
- http://marc.info/?l=bugtraq&m=105838862201266&w=2
- http://marc.info/?l=ntbugtraq&m=105838590030409&w=2
- http://pivx.com/larholm/adv/TL006
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-028
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A117
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0029.html
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0031.html
- http://marc.info/?l=bugtraq&m=105838519729525&w=2
- http://marc.info/?l=bugtraq&m=105838862201266&w=2
- http://marc.info/?l=ntbugtraq&m=105838590030409&w=2
- http://pivx.com/larholm/adv/TL006
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-028
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A117
JSON original (NVD)
Mostrar
{
"id": "CVE-2003-0526",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2003-08-18T04:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0029.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0031.html",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=105838519729525&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=105838862201266&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=ntbugtraq&m=105838590030409&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://pivx.com/larholm/adv/TL006",
"source": "cve@mitre.org"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-028",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A117",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0029.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0031.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=105838519729525&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=105838862201266&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=ntbugtraq&m=105838590030409&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://pivx.com/larholm/adv/TL006",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-028",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A117",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for \"500 Internal Server error\" or (2) 404.htm for \"404 Not Found.\""
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Microsoft Internet Security and Acceleration (ISA) Server 2000 permite a atacantes remotos inyectar script web arbitrario en la porción del nombre de dominio, que no es limpiado adecuadamente en las páginas de error por defecto (1) 500.htm (\"500 Internal Server Error\") o (2) 404.htm (\"404 No encontrado\")."
}
],
"lastModified": "2026-06-16T22:02:22.173",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:isa_server:2000:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80744BD9-85A9-4E33-8C35-59C8C112AC62"
},
{
"criteria": "cpe:2.3:a:microsoft:isa_server:2000:fp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "098032EB-F5E2-4061-8DE2-BEDA6B192EA9"
},
{
"criteria": "cpe:2.3:a:microsoft:isa_server:2000:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F2A1D83-7D2F-4408-B93E-FB53F724EB58"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}