CVE-2003-1026

Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
References
Link Resource
http://marc.info/?l=bugtraq&m=106979349517578&w=2
http://marc.info/?l=bugtraq&m=107038202225587&w=2
http://www.kb.cert.org/vuls/id/784102 Third Party Advisory US Government Resource
http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu
http://www.us-cert.gov/cas/techalerts/TA04-033A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004
https://exchange.xforce.ibmcloud.com/vulnerabilities/13846
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A630
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A643
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A687
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A689
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A745
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A774
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A805
http://marc.info/?l=bugtraq&m=106979349517578&w=2
http://marc.info/?l=bugtraq&m=107038202225587&w=2
http://www.kb.cert.org/vuls/id/784102 Third Party Advisory US Government Resource
http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu
http://www.us-cert.gov/cas/techalerts/TA04-033A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004
https://exchange.xforce.ibmcloud.com/vulnerabilities/13846
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A630
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A643
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A687
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A689
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A745
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A774
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A805
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:46

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=106979349517578&w=2 - () http://marc.info/?l=bugtraq&m=106979349517578&w=2 -
References () http://marc.info/?l=bugtraq&m=107038202225587&w=2 - () http://marc.info/?l=bugtraq&m=107038202225587&w=2 -
References () http://www.kb.cert.org/vuls/id/784102 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/784102 - Third Party Advisory, US Government Resource
References () http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu - () http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu -
References () http://www.us-cert.gov/cas/techalerts/TA04-033A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA04-033A.html - US Government Resource
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/13846 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/13846 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A630 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A630 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A643 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A643 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A687 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A687 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A689 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A689 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A745 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A745 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A774 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A774 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A805 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A805 -

Information

Published : 2004-01-20 05:00

Updated : 2024-11-20 23:46


NVD link : CVE-2003-1026

Mitre link : CVE-2003-1026

CVE.ORG link : CVE-2003-1026


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • ie
CWE
CWE-264

Permissions, Privileges, and Access Controls