CVE-2003-1028
The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 19.05% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/ie · microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=106979428718705&w=2
- http://marc.info/?l=bugtraq&m=106979624321665&w=2
- http://marc.info/?l=bugtraq&m=107038202225587&w=2
- http://www.osvdb.org/7890
- http://www.safecenter.net/UMBRELLAWEBV4/threadid10008
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13847
- http://marc.info/?l=bugtraq&m=106979428718705&w=2
- http://marc.info/?l=bugtraq&m=106979624321665&w=2
- http://marc.info/?l=bugtraq&m=107038202225587&w=2
- http://www.osvdb.org/7890
- http://www.safecenter.net/UMBRELLAWEBV4/threadid10008
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13847
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.