CVE detail
CVE-2004-1133 — CVE-2004-1133
Published 2005-01-10 · Modified 2026-06-16 · Vendor microsoft · Product w3who.dll · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0981
EPSS probability
exploitation probability, 30d
95.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web script via (1) HTTP headers such as "Connection" or (2) invalid parameters whose values are echoed in the resulting error message.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References