Vulnerabilities > CVE-2002-0026 - Unspecified vulnerability in Microsoft Internet Explorer 5.5/6.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft

Summary

Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.

Vulnerable Configurations

Part Description Count
Application
Microsoft
2

Oval

  • accepted2014-02-24T04:00:10.389-05:00
    classvulnerability
    contributors
    • nameDavid Proulx
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.
    familywindows
    idoval:org.mitre.oval:def:12
    statusaccepted
    submitted2003-11-12T12:00:00.000-04:00
    titleIE v5.5,SP2 Forced Script Execution
    version66
  • accepted2014-02-24T04:03:12.135-05:00
    classvulnerability
    contributors
    • nameDavid Proulx
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.
    familywindows
    idoval:org.mitre.oval:def:23
    statusaccepted
    submitted2003-11-12T12:00:00.000-04:00
    titleIE v5.5 Forced Script Execution
    version66
  • accepted2014-02-24T04:03:14.826-05:00
    classvulnerability
    contributors
    • nameDavid Proulx
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.
    familywindows
    idoval:org.mitre.oval:def:32
    statusaccepted
    submitted2003-11-12T05:00:00.000-04:00
    titleIE v6.0 Forced Script Execution
    version66