CVE Database
/

CVE-2002-0648

Back to search

CVE-2002-0648

Published: Apr 2, 2003

Modified: Aug 8, 2024

PUBLISHED

Description

The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.

VendorProductVersions

n/a

n/a

affected
n/a

References

MS02-047
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:1207
vdb-entry
signature
x_refsource_OVAL
5560
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:1026
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:776
vdb-entry
signature
x_refsource_OVAL
ie-xml-redirect-read-files(9936)
vdb-entry
x_refsource_XF
oval:org.mitre.oval:def:1148
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:608
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now