4.3
CVSSv2

CVE-2003-0446

Published: 24/07/2003 Updated: 23/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote malicious users to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 6.0

microsoft internet explorer 5.5

Exploits

source: wwwsecurityfocuscom/bid/7938/info A vulnerability has been reported for the Microsoft Internet Explorer that may result in cross-site scripting attacks If IE, using the MSXML parser, is unable to parse the requested XML file, it will display a parse error that also includes the URL of the requested XML file In some cases malici ...