Vulnerabilities > CVE-2002-0023 - Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5/6.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
microsoft
exploit available

Summary

Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.

Exploit-Db

descriptionMicrosoft Internet Explorer 5/6 GetObject File Disclosure Vulnerability. CVE-2002-0023. Remote exploit for windows platform
idEDB-ID:21195
last seen2016-02-02
modified2002-01-01
published2002-01-01
reporterGeorgi Guninski
sourcehttps://www.exploit-db.com/download/21195/
titleMicrosoft Internet Explorer 5/6 GetObject File Disclosure Vulnerability

Oval

  • accepted2014-02-24T04:00:22.161-05:00
    classvulnerability
    contributors
    • nameDavid Proulx
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.
    familywindows
    idoval:org.mitre.oval:def:17
    statusaccepted
    submitted2003-11-12T05:00:00.000-04:00
    titleIE GetObject Security Bypass
    version66
  • accepted2014-02-24T04:03:17.744-05:00
    classvulnerability
    contributors
    • nameDavid Proulx
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.
    familywindows
    idoval:org.mitre.oval:def:40
    statusaccepted
    submitted2003-11-12T12:00:00.000-04:00
    titleIE v5.5,SP2 GetObject File Retrieval
    version66
  • accepted2014-02-24T04:03:20.775-05:00
    classvulnerability
    contributors
    • nameDavid Proulx
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.
    familywindows
    idoval:org.mitre.oval:def:50
    statusaccepted
    submitted2003-11-12T12:00:00.000-04:00
    titleIE v5.01 GetObject File Retrieval
    version66
  • accepted2014-02-24T04:03:26.783-05:00
    classvulnerability
    contributors
    • nameDavid Proulx
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.
    familywindows
    idoval:org.mitre.oval:def:77
    statusaccepted
    submitted2003-11-12T12:00:00.000-04:00
    titleIE v5.5 GetObject File Retrieval
    version66