Back

CVE-2000-0942

The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.

Published: Dec 19, 2000 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
microsoft indexing_service *

GitHub Security Advisory GHSA-rp27-2r6m-x965

The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote...

Risk Scores

CVSS Score 5.1 / 10
EPSS Score 36.88%

Top 3% most likely to be exploited

Threat Score 31.5 / 100

Data Sources

NVD EPSS GitHub