5

CVE-2003-1028

The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Ie Version 6.0 Update sp1
Microsoft ≫ Internet Explorer Version 5.0
Microsoft ≫ Internet Explorer Version 5.0.1
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp1
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp2
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp3
Microsoft ≫ Internet Explorer Version 5.5
Microsoft ≫ Internet Explorer Version 5.5 Update sp1
Microsoft ≫ Internet Explorer Version 5.5 Update sp2
Microsoft ≫ Internet Explorer Version 6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.05% 0.969
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=107038202225587&w=2
http://marc.info/?l=bugtraq&m=106979428718705&w=2
http://marc.info/?l=bugtraq&m=106979624321665&w=2
http://www.osvdb.org/7890
http://www.safecenter.net/UMBRELLAWEBV4/threadid10008
https://exchange.xforce.ibmcloud.com/vulnerabilities/13847