Back
CVE-2003-0009
Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.
Published: Mar 7, 2003
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_me | * |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
GitHub Security Advisory GHSA-38g3-w7mj-hw2f
Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me...
References (14)
- http://marc.info/?l=bugtraq&m=104636383018686&w=2
- http://www.ciac.org/ciac/bulletins/n-047.shtml
- http://www.iss.net/security_center/static/11425.php Vendor Advisory
- http://www.kb.cert.org/vuls/id/489721 US Government Resource
- http://www.osvdb.org/6074
- http://www.securityfocus.com/bid/6966 Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-006
- http://marc.info/?l=bugtraq&m=104636383018686&w=2
- http://www.ciac.org/ciac/bulletins/n-047.shtml
- http://www.iss.net/security_center/static/11425.php Vendor Advisory
- http://www.kb.cert.org/vuls/id/489721 US Government Resource
- http://www.osvdb.org/6074
- http://www.securityfocus.com/bid/6966 Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-006
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
16.48%
Top 3% most likely to be exploited
Threat Score
32.1 / 100
Data Sources
NVD
EPSS
GitHub