6.4
CVSSv2

CVE-2002-0976

Published: 24/09/2002 Updated: 23/07/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Internet Explorer 4.0 and later allows remote malicious users to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 5.0.1

microsoft internet explorer 5.5

microsoft internet explorer 4.0

microsoft internet explorer 4.0.1

microsoft internet explorer 5.0

microsoft internet explorer 6.0

Exploits

source: wwwsecurityfocuscom/bid/5490/info A problem in Microsoft Internet Explorer could lead to the disclosure of sensitive information Due to the design of the datasource applet, it may be possible for a user to view the contents of local files via a remote page By building a custom-crafted page that specifies the code base as the lo ...