CVE-2003-0116

Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:43

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/244729 - US Government Resource () http://www.kb.cert.org/vuls/id/244729 - US Government Resource
References () http://www.securityfocus.com/archive/1/301945 - () http://www.securityfocus.com/archive/1/301945 -
References () http://www.securityfocus.com/bid/6306 - Exploit, Patch, Vendor Advisory () http://www.securityfocus.com/bid/6306 - Exploit, Patch, Vendor Advisory
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015 -

Information

Published : 2003-05-12 04:00

Updated : 2024-11-20 23:43


NVD link : CVE-2003-0116

Mitre link : CVE-2003-0116

CVE.ORG link : CVE-2003-0116


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • ie