Vulnerabilities > CVE-2002-1187 - Unspecified vulnerability in Microsoft Internet Explorer
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
exploit available
Summary
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Exploit-Db
description | MS IE 5 IFrame/Frame Cross-Site/Zone Script Execution Vulnerability. CVE-2002-1187. Remote exploit for windows platform |
id | EDB-ID:21777 |
last seen | 2016-02-02 |
modified | 2002-09-09 |
published | 2002-09-09 |
reporter | GreyMagic Software |
source | https://www.exploit-db.com/download/21777/ |
title | Microsoft Internet Explorer 5 IFrame/Frame Cross-Site/Zone Script Execution Vulnerability |
Oval
accepted 2014-02-24T04:00:26.679-05:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Maria Mikhno organization ALTX-SOFT
description element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource. family windows id oval:org.mitre.oval:def:203 status accepted submitted 2004-01-27T05:00:00.000-04:00 title IE v6.0 Frames Cross-site Scripting Vulnerability version 67 accepted 2014-02-24T04:03:11.752-05:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Maria Mikhno organization ALTX-SOFT
description element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource. family windows id oval:org.mitre.oval:def:225 status accepted submitted 2004-01-27T12:00:00.000-04:00 title IE v5.5 Frames Cross-site Scripting Vulnerability version 66
References
- http://marc.info/?l=bugtraq&m=103158601431054&w=2
- http://marc.info/?l=bugtraq&m=103158601431054&w=2
- http://www.iss.net/security_center/static/10066.php
- http://www.iss.net/security_center/static/10066.php
- http://www.osvdb.org/2998
- http://www.osvdb.org/2998
- http://www.securityfocus.com/bid/5672
- http://www.securityfocus.com/bid/5672
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A203
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A203
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A225
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A225