10
CVSSv2

CVE-1999-0347

Published: 26/01/1999 Updated: 18/10/2016
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Internet Explorer 4.01 allows remote malicious users to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.

Exploits

source: wwwsecurityfocuscom/bid/197/info On January 28, 1999, Georgi Guninski originally reported a vulnerability in Internet Explorer 4x Internet Explorer 4x's implentation of Cross-frame security could be bypassed if "%01" is appended to an arbitrary URL If the specially malformed URL is inserted in a javascript after an 'about:' st ...