Vulnerabilities > CVE-2003-0446 - Unspecified vulnerability in Microsoft Internet Explorer 5.5/6.0

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
microsoft
exploit available

Summary

Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.

Vulnerable Configurations

Part Description Count
Application
Microsoft
2

Exploit-Db

descriptionMicrosoft Internet Explorer 5/6 MSXML XML File Parsing Cross-Site Scripting Vulnerability. CVE-2003-0446. Remote exploit for windows platform
idEDB-ID:22783
last seen2016-02-02
modified2003-06-17
published2003-06-17
reporterGreyMagic Software
sourcehttps://www.exploit-db.com/download/22783/
titleMicrosoft Internet Explorer 5/6 MSXML XML File Parsing Cross-Site Scripting Vulnerability