CVE-2002-0723
Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 15.03% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://www.iss.net/security_center/static/9537.phpVendor Advisory
- http://www.securityfocus.com/bid/5196
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-047
- http://www.iss.net/security_center/static/9537.phpVendor Advisory
- http://www.securityfocus.com/bid/5196
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-047
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.