Vulnerabilities > CVE-2002-0648 - Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5/6.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
Exploit-Db
description | Microsoft Internet Explorer 5/6 XML Redirect File Disclosure Vulnerability. CVE-2002-0648 . Remote exploit for windows platform |
id | EDB-ID:21749 |
last seen | 2016-02-02 |
modified | 2002-08-23 |
published | 2002-08-23 |
reporter | GreyMagic Software |
source | https://www.exploit-db.com/download/21749/ |
title | Microsoft Internet Explorer 5/6 XML Redirect File Disclosure Vulnerability |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS05-025.NASL |
description | The remote host is missing IE Cumulative Security Update 883939. The remote version of IE is vulnerable to several flaws that could allow an attacker to execute arbitrary code on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18490 |
published | 2005-06-14 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18490 |
title | MS05-025: Cumulative Security Update for Internet Explorer (883939) |
code |
|
Oval
accepted 2014-02-24T04:00:06.804-05:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Robert L. Hollis organization ThreatGuard, Inc. name Maria Mikhno organization ALTX-SOFT
description data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file. family windows id oval:org.mitre.oval:def:1026 status accepted submitted 2005-06-22T12:00:00.000-04:00 title IE5.01,SP3 File Disclosure via Redirects Vulnerability version 67 accepted 2014-02-24T04:00:09.649-05:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Maria Mikhno organization ALTX-SOFT
description data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file. family windows id oval:org.mitre.oval:def:1148 status accepted submitted 2005-06-22T12:00:00.000-04:00 title IE6 Installed XP,SP2 File Disclosure via Redirects Vulnerability version 66 accepted 2014-02-24T04:00:10.519-05:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Robert L. Hollis organization ThreatGuard, Inc. name Maria Mikhno organization ALTX-SOFT
description data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file. family windows id oval:org.mitre.oval:def:1207 status accepted submitted 2005-06-22T12:00:00.000-04:00 title IE6,SP1 File Disclosure via Redirects Vulnerability version 67 accepted 2014-02-24T04:03:24.264-05:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Robert L. Hollis organization ThreatGuard, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc. name Maria Mikhno organization ALTX-SOFT
description data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file. family windows id oval:org.mitre.oval:def:608 status accepted submitted 2005-06-22T12:00:00.000-04:00 title IE6 for Server 2003 File Disclosure via Redirects Vulnerability version 71 accepted 2014-02-24T04:03:27.096-05:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Robert L. Hollis organization ThreatGuard, Inc. name Maria Mikhno organization ALTX-SOFT
description data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file. family windows id oval:org.mitre.oval:def:776 status accepted submitted 2005-06-22T12:00:00.000-04:00 title IE5.01,SP4 File Disclosure via Redirects Vulnerability version 67
References
- http://www.securityfocus.com/bid/5560
- http://www.iss.net/security_center/static/9936.php
- http://marc.info/?l=bugtraq&m=103011639524314&w=2
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A776
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A608
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1207
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1148
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1026
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-047