CVE-2003-0815

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.
References
Link Resource
http://marc.info/?l=bugtraq&m=106321757619047&w=2
http://marc.info/?l=bugtraq&m=106322542104656&w=2
http://secunia.com/advisories/10192
http://securitytracker.com/id?1007687
http://www.ciac.org/ciac/bulletins/o-021.shtml
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html
http://www.osvdb.org/7888
http://www.osvdb.org/7889
http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM
http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM
http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM
http://www.securityfocus.com/archive/1/337086
http://www.securityfocus.com/bid/9014 Patch Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048
https://exchange.xforce.ibmcloud.com/vulnerabilities/13676
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472
http://marc.info/?l=bugtraq&m=106321757619047&w=2
http://marc.info/?l=bugtraq&m=106322542104656&w=2
http://secunia.com/advisories/10192
http://securitytracker.com/id?1007687
http://www.ciac.org/ciac/bulletins/o-021.shtml
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html
http://www.osvdb.org/7888
http://www.osvdb.org/7889
http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM
http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM
http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM
http://www.securityfocus.com/archive/1/337086
http://www.securityfocus.com/bid/9014 Patch Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048
https://exchange.xforce.ibmcloud.com/vulnerabilities/13676
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:45

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=106321757619047&w=2 - () http://marc.info/?l=bugtraq&m=106321757619047&w=2 -
References () http://marc.info/?l=bugtraq&m=106322542104656&w=2 - () http://marc.info/?l=bugtraq&m=106322542104656&w=2 -
References () http://secunia.com/advisories/10192 - () http://secunia.com/advisories/10192 -
References () http://securitytracker.com/id?1007687 - () http://securitytracker.com/id?1007687 -
References () http://www.ciac.org/ciac/bulletins/o-021.shtml - () http://www.ciac.org/ciac/bulletins/o-021.shtml -
References () http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html - () http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html -
References () http://www.osvdb.org/7888 - () http://www.osvdb.org/7888 -
References () http://www.osvdb.org/7889 - () http://www.osvdb.org/7889 -
References () http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM - () http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM -
References () http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM - () http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM -
References () http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM - () http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM -
References () http://www.securityfocus.com/archive/1/337086 - () http://www.securityfocus.com/archive/1/337086 -
References () http://www.securityfocus.com/bid/9014 - Patch, Vendor Advisory () http://www.securityfocus.com/bid/9014 - Patch, Vendor Advisory
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/13676 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/13676 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472 -

Information

Published : 2004-02-03 05:00

Updated : 2024-11-20 23:45


NVD link : CVE-2003-0815

Mitre link : CVE-2003-0815

CVE.ORG link : CVE-2003-0815


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • ie