7.5

CVE-2002-0188

Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the second variant of the "Content Disposition" vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 5.01
Microsoft ≫ Internet Explorer Version 5.01 Update sp1
Microsoft ≫ Internet Explorer Version 5.01 Update sp2
Microsoft ≫ Internet Explorer Version 6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.35% 0.966
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2002-05/0126.html
http://www.iss.net/security_center/static/9086.php
Vendor Advisory
http://www.lac.co.jp/security/english/snsadv_e/48_e.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-023