Synopsis
The remote web server is affected by a cross-site scripting vulnerability.
Description
This IIS Server appears to be vulnerable to a cross-site scripting attack due to an error in the handling of overly-long requests on an idc file. It is possible to inject JavaScript in the URL, that will appear in the resulting page.
Solution
Upgrade to Windows 2000 SP3 or higher, as this reportedly fixes the issue.
Plugin Details
File Name: iis_xss_idc.nasl
Configuration: Enable thorough checks
Supported Sensors: Nessus
Vulnerability Information
CPE: cpe:/a:microsoft:iis
Exploit Ease: No exploit is required
Reference Information
BID: 5900
CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990