CVE-2003-0768

Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.

Scoring

CVSS base score
0.69
EPSS probability
17.17%
Published
2003-09-12
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs