Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2003-0815
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2003-0815

Description:
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/13676

ST
  1007687

SAID
  Secunia Advisory: SA10192

OVAL
  http://oval.mitre.org/oval/definitions/data/oval359.html
  http://oval.mitre.org/oval/definitions/data/oval351.html
  http://oval.mitre.org/oval/definitions/data/oval352.html
  http://oval.mitre.org/oval/definitions/data/oval353.html
  http://oval.mitre.org/oval/definitions/data/oval356.html
  http://oval.mitre.org/oval/definitions/data/oval357.html
  http://oval.mitre.org/oval/definitions/data/oval472.html

OSVDB
  7889
  7888

MS
  http://www.microsoft.com/technet/security/bulletin/ms03-048.asp

MISC
  http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM
  http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM
  http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM

CIAC
  http://www.ciac.org/ciac/bulletins/o-021.shtml

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=106322542104656&w=2
  http://www.securityfocus.com/archive/1/337086
  http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html
  http://marc.theaimsgroup.com/?l=bugtraq&m=106321757619047&w=2

BID
  9014


Return to the previous page.