Oval Definition:
oval:org.mitre.oval:def:225
Revision Date
:
2014-02-24
Version
:
43
Title
:
IE v5.5 Frames Cross-site Scripting Vulnerability
Description
:
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the
or
element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2002-1187
Platform(s)
:
Microsoft Windows 2000
Product(s)
:
Microsoft Internet Explorer
Definition Synopsis
Internet Explorer 5.5 Installed
Internet Explorer 5.5 Installed
OR
Internet Explorer 5.5 Installed
OR
Internet Explorer 5.5 Installed
OR
Internet Explorer 5.5 Service Pack 2 is installed
AND
the version of mshtml.dll is less than 5.50.4922.900
AND
NOT
the patch q328970 is installed (Installed Components key)
AND
NOT
the patch q324929 is installed (Installed Components key)
AND
NOT
the patch q810847 is installed (Installed Components key)
AND
NOT
the patch q813489 is installed (Installed Components key)
AND
NOT
the patch q818529 is installed (Installed Components key)
AND
NOT
the patch q822925 is installed (Installed Components key)
AND
NOT
the patch q828750 is installed (Installed Components key)
AND
NOT
the patch q824145 is installed (Installed Components key)
BACK