7.5
CVSSv2

CVE-2002-0723

Published: 24/09/2002 Updated: 23/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote malicious users to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 5.5

microsoft internet explorer 6.0

Exploits

source: wwwsecurityfocuscom/bid/5196/info Microsoft Internet Explorer allows script code to violate the same origin policy through usage of the HTML OBJECT tag Malicious script code may obtain a legitimate reference to an embedded object containing a web page from the same domain This script may then change the location of the embedded ...