Vulnerabilities > CVE-2002-0980 - Unspecified vulnerability in Microsoft Internet Explorer 5.5/6.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
exploit available

Summary

The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.

Vulnerable Configurations

Part Description Count
Application
Microsoft
4

Exploit-Db

descriptionMicrosoft Outlook Express 5/6 MHTML URL Handler File Rendering Vulnerability. CVE-2002-0980. Remote exploit for windows platform
idEDB-ID:21711
last seen2016-02-02
modified2002-08-15
published2002-08-15
reporterhttp-equiv
sourcehttps://www.exploit-db.com/download/21711/
titleMicrosoft Outlook Express 5/6 MHTML URL Handler File Rendering Vulnerability