Vulnerabilities > CVE-2002-1254 - Unspecified vulnerability in Microsoft IE and Internet Explorer

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
exploit available

Summary

Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."

Vulnerable Configurations

Part Description Count
Application
Microsoft
5

Exploit-Db

descriptionMicrosoft Internet Explorer 5/6 Cached Objects Zone Bypass Vulnerability. CVE-2002-1254. Remote exploit for windows platform
idEDB-ID:21959
last seen2016-02-02
modified2002-10-22
published2002-10-22
reporterGreyMagic Software
sourcehttps://www.exploit-db.com/download/21959/
titleMicrosoft Internet Explorer 5/6 Cached Objects Zone Bypass Vulnerability

Oval

  • accepted2014-02-24T04:03:17.188-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."
    familywindows
    idoval:org.mitre.oval:def:388
    statusaccepted
    submitted2004-01-27T05:00:00.000-04:00
    titleIE v6.0 Cross Domain Verification via Cached Methods Vulnerability
    version67
  • accepted2014-02-24T04:03:17.813-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."
    familywindows
    idoval:org.mitre.oval:def:408
    statusaccepted
    submitted2004-01-27T12:00:00.000-04:00
    titleIE v5.5 Cross Domain Verification via Cached Methods Vulnerability
    version66