Vulnerabilities > CVE-2002-0057 - Unspecified vulnerability in Microsoft products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
microsoft
nessus

Summary

XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.

Nessus

  • NASL familyWindows : Microsoft Bulletins
    NASL idSMB_NT_MS02-005.NASL
    descriptionThe Cumulative Patch for IE is not applied on the remote host. Impact of vulnerability : Run code of attacker
    last seen2020-06-01
    modified2020-06-02
    plugin id10861
    published2002-02-13
    reporterThis script is Copyright (C) 2002-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/10861
    titleMS02-005: MSIE 5.01 5.5 6.0 Cumulative Patch (890923)
  • NASL familyWindows : Microsoft Bulletins
    NASL idSMB_NT_MS02-008.NASL
    descriptionThe remote host is running a version of Internet Explorer that could allow an attacker to read local files on the remote host. To exploit this flaw, an attacker would need to lure a victim on the remote system into visiting a rogue website.
    last seen2020-06-01
    modified2020-06-02
    plugin id10866
    published2002-02-24
    reporterThis script is Copyright (C) 2002-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/10866
    titleMS02-008: XML Core Services patch (318203)