7.5
CVE-2002-1217
- EPSS 49.81%
- Veröffentlicht 28.10.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:58:56
- Erkennungen
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 5.5
Microsoft ≫ Internet Explorer Version 5.5 Update sp1
Microsoft ≫ Internet Explorer Version 5.5 Update sp2
Microsoft ≫ Internet Explorer Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 49.81% | 0.988 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0024.html
http://marc.info/?l=bugtraq&m=103470310417576&w=2
http://marc.info/?l=ntbugtraq&m=103470202010570&w=2
http://security.greymagic.com/adv/gm011-ie/
http://www.ciac.org/ciac/bulletins/n-018.shtml
http://www.iss.net/security_center/static/10371.php
http://www.securityfocus.com/bid/5963
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A272
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A333