Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.428
EPSS Ranking 97.3%