Vulnerabilities > CVE-2002-0976 - Unspecified vulnerability in Microsoft Internet Explorer

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
microsoft
exploit available

Summary

Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.

Exploit-Db

descriptionMicrosoft Internet Explorer 4/5/6 XML Datasource Applet File Disclosure Vulnerability. CVE-2002-0976. Local exploit for windows platform
idEDB-ID:21721
last seen2016-02-02
modified2002-08-17
published2002-08-17
reporterJelmer
sourcehttps://www.exploit-db.com/download/21721/
titleMicrosoft Internet Explorer 4/5/6 XML Datasource Applet File Disclosure Vulnerability