2.6
CVSSv2

CVE-2001-0089

Published: 16/02/2001 Updated: 23/07/2021
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

Internet Explorer 5.0 up to and including 5.5 allows remote malicious users to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer

microsoft internet explorer 5.0

microsoft internet explorer 5.01

Exploits

<!-- source: wwwsecurityfocuscom/bid/2045/info One of the ways users submit information to remote websites is through the INPUT type form options Users can upload files to remote webservers with the input type=FILE option Due to a design error in the implementation of the INPUT TYPE=FILE variable , it is possible for a website opera ...