5
CVSSv2

CVE-2001-0149

Published: 02/06/2001 Updated: 23/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Windows Scripting Host in Internet Explorer 5.5 and previous versions allows remote malicious users to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer

Exploits

source: wwwsecurityfocuscom/bid/1718/info It is possible for an outside attacker to view known files on a remote system if the target user visits a website or opens an email containing a specially formed script containing the JScript function 'GetObject()' and the ActiveX object 'htmlfile' Microsoft Internet Explorer or Outlook Express ...