Back to search
CVE-2002-0648
Published: Apr 2, 2003
Modified: Aug 8, 2024
PUBLISHED
Description
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
MS02-047
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:1207
vdb-entry
signature
x_refsource_OVAL
5560
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:1026
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:776
vdb-entry
signature
x_refsource_OVAL
ie-xml-redirect-read-files(9936)
vdb-entry
x_refsource_XF
oval:org.mitre.oval:def:1148
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:608
vdb-entry
signature
x_refsource_OVAL
20020823 Accessing remote/local content in IE (GM#009-IE)
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now