Vulnerabilities > CVE-2002-1217 - Unspecified vulnerability in Microsoft Internet Explorer 5.5/6.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
exploit available

Summary

Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.

Vulnerable Configurations

Part Description Count
Application
Microsoft
4

Exploit-Db

descriptionMS Internet Explorer 5/6 Unauthorized Document Object Model Access Vulnerability. CVE-2002-1217. Remote exploit for windows platform
idEDB-ID:21940
last seen2016-02-02
modified2002-10-15
published2002-10-15
reporterGreyMagic Software
sourcehttps://www.exploit-db.com/download/21940/
titleMicrosoft Internet Explorer 5/6 Unauthorized Document Object Model Access Vulnerability

Oval

  • accepted2014-02-24T04:03:13.673-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    description domain restrictions.
    familywindows
    idoval:org.mitre.oval:def:272
    statusaccepted
    submitted2004-01-27T05:00:00.000-04:00
    titleIE v6.0 Domain Restriction Bypass Cross-Frame Scripting
    version67
  • accepted2014-02-24T04:03:15.073-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    description domain restrictions.
    familywindows
    idoval:org.mitre.oval:def:333
    statusaccepted
    submitted2004-01-27T12:00:00.000-04:00
    titleIE v5.5 Domain Restriction Bypass Cross-Frame Scripting
    version66