5

CVE-2002-0057

XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftInternet Explorer Version6.0
MicrosoftSql Server Version2000
MicrosoftSql Server Version2000 Updatesp1
MicrosoftSql Server Version2000 Updatesp2
MicrosoftXml Core Services Version2.6
MicrosoftXml Core Services Version3.0
MicrosoftXml Core Services Version4.0
MicrosoftWindows Xp Editionhome
MicrosoftWindows Xp Updategold Editionprofessional
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 41.76% 0.973
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N