← All CVEs

CVE-2001-1325

high · 7.5

Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).

7.5
CVSS
27.3%
EPSS (exploit prob.)
98th
EPSS percentile
2001-04-20
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
microsoftinternet_explorer5.0
microsoftinternet_explorer5.5
microsoftoutlook_express5.0
microsoftoutlook_express5.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2001-1325