Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2003-06/0120.html - | |
References | () http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005762.html - | |
References | () http://marc.info/?l=bugtraq&m=105585986015421&w=2 - | |
References | () http://marc.info/?l=bugtraq&m=105595990924165&w=2 - | |
References | () http://marc.info/?l=ntbugtraq&m=105585001905002&w=2 - | |
References | () http://secunia.com/advisories/9055 - | |
References | () http://security.greymagic.com/adv/gm013-ie/ - Exploit, Vendor Advisory | |
References | () http://www.osvdb.org/3065 - | |
References | () http://www.securityfocus.com/bid/7938 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/12334 - |
Information
Published : 2003-07-24 04:00
Updated : 2024-11-20 23:44
NVD link : CVE-2003-0446
Mitre link : CVE-2003-0446
CVE.ORG link : CVE-2003-0446
JSON object : View
Products Affected
microsoft
- internet_explorer
CWE