Vulnerabilities > CVE-2000-0028 - Unspecified vulnerability in Microsoft IE and Internet Explorer

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
high complexity
microsoft
exploit available

Summary

Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

Exploit-Db

descriptionMS IE 4/5/5.5/5.0.1 external.NavigateAndFind() Cross-Frame Vulnerability. CVE-2000-0028. Remote exploits for multiple platform
idEDB-ID:19686
last seen2016-02-02
modified1999-12-22
published1999-12-22
reporterGeorgi Guninski
sourcehttps://www.exploit-db.com/download/19686/
titleMicrosoft Internet Explorer 4/5/5.5/5.0.1 external.NavigateAndFind Cross-Frame Vulnerability