CVE-2002-2031

Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a script tag with a src parameter that references a non-JavaScript file, then using the onError event handler to monitor the results.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:42

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2002-01/0019.html - Exploit () http://archives.neohapsis.com/archives/bugtraq/2002-01/0019.html - Exploit
References () http://www.iss.net/security_center/static/7784.php - () http://www.iss.net/security_center/static/7784.php -
References () http://www.securityfocus.com/bid/3779 - Exploit () http://www.securityfocus.com/bid/3779 - Exploit

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:42


NVD link : CVE-2002-2031

Mitre link : CVE-2002-2031

CVE.ORG link : CVE-2002-2031


JSON object : View

Products Affected

microsoft

  • internet_explorer