CVE-2003-0816

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.
References
Link Resource
http://marc.info/?l=bugtraq&m=106321638416884&w=2
http://marc.info/?l=bugtraq&m=106321693517858&w=2
http://marc.info/?l=bugtraq&m=106321781819727&w=2
http://marc.info/?l=bugtraq&m=106321882821788&w=2
http://marc.info/?l=bugtraq&m=106322063729496&w=2
http://marc.info/?l=bugtraq&m=106322240132721&w=2
http://secunia.com/advisories/10192
http://securitytracker.com/id?1007687
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html
http://www.kb.cert.org/vuls/id/652452 Patch Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/771604 US Government Resource
http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm
http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM
http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm
http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM
http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM
http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM
http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM
http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM
http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM
http://www.securityfocus.com/archive/1/336937
http://www.securityfocus.com/archive/1/337086
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A361
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A362
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A363
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A409
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A416
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A459
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A479
http://marc.info/?l=bugtraq&m=106321638416884&w=2
http://marc.info/?l=bugtraq&m=106321693517858&w=2
http://marc.info/?l=bugtraq&m=106321781819727&w=2
http://marc.info/?l=bugtraq&m=106321882821788&w=2
http://marc.info/?l=bugtraq&m=106322063729496&w=2
http://marc.info/?l=bugtraq&m=106322240132721&w=2
http://secunia.com/advisories/10192
http://securitytracker.com/id?1007687
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html
http://www.kb.cert.org/vuls/id/652452 Patch Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/771604 US Government Resource
http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm
http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM
http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm
http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM
http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM
http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM
http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM
http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM
http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM
http://www.securityfocus.com/archive/1/336937
http://www.securityfocus.com/archive/1/337086
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A361
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A362
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A363
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A409
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A416
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A459
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A479
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:45

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=106321638416884&w=2 - () http://marc.info/?l=bugtraq&m=106321638416884&w=2 -
References () http://marc.info/?l=bugtraq&m=106321693517858&w=2 - () http://marc.info/?l=bugtraq&m=106321693517858&w=2 -
References () http://marc.info/?l=bugtraq&m=106321781819727&w=2 - () http://marc.info/?l=bugtraq&m=106321781819727&w=2 -
References () http://marc.info/?l=bugtraq&m=106321882821788&w=2 - () http://marc.info/?l=bugtraq&m=106321882821788&w=2 -
References () http://marc.info/?l=bugtraq&m=106322063729496&w=2 - () http://marc.info/?l=bugtraq&m=106322063729496&w=2 -
References () http://marc.info/?l=bugtraq&m=106322240132721&w=2 - () http://marc.info/?l=bugtraq&m=106322240132721&w=2 -
References () http://secunia.com/advisories/10192 - () http://secunia.com/advisories/10192 -
References () http://securitytracker.com/id?1007687 - () http://securitytracker.com/id?1007687 -
References () http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html - () http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html -
References () http://www.kb.cert.org/vuls/id/652452 - Patch, Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/652452 - Patch, Third Party Advisory, US Government Resource
References () http://www.kb.cert.org/vuls/id/771604 - US Government Resource () http://www.kb.cert.org/vuls/id/771604 - US Government Resource
References () http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm - () http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm -
References () http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM - () http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM -
References () http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm - () http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm -
References () http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM - () http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM -
References () http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM - () http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM -
References () http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM - () http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM -
References () http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM - () http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM -
References () http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM - () http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM -
References () http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM - () http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM -
References () http://www.securityfocus.com/archive/1/336937 - () http://www.securityfocus.com/archive/1/336937 -
References () http://www.securityfocus.com/archive/1/337086 - () http://www.securityfocus.com/archive/1/337086 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A361 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A361 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A362 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A362 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A363 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A363 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A409 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A409 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A416 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A416 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A459 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A459 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A479 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A479 -

Information

Published : 2004-02-03 05:00

Updated : 2024-11-20 23:45


NVD link : CVE-2003-0816

Mitre link : CVE-2003-0816

CVE.ORG link : CVE-2003-0816


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • ie