Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2002-0648
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2002-0648

Description:
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.

CVE Status:
Entry

References:

XF
  http://www.iss.net/security_center/static/9936.php

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1026
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1148
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1207
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:608
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:776

MS
  http://www.microsoft.com/technet/security/bulletin/ms02-047.asp

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=103011639524314&w=2

BID
  5560


Return to the previous page.