Oval Definition:
oval:org.mitre.oval:def:40
Revision Date
:
2014-02-24
Version
:
43
Title
:
IE v5.5,SP2 GetObject File Retrieval
Description
:
Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2002-0023
Platform(s)
:
Microsoft Windows 2000
Product(s)
:
Microsoft Internet Explorer
Definition Synopsis
Internet Explorer 5.5 Service Pack 2 is installed
AND
the version of mshtml.dll is less than 5.50.4913.1100
AND
NOT
the patch q316059 is installed (Installed Components key)
AND
NOT
the patch q319282 is installed (Installed Components key)
AND
NOT
the patch q321232 is installed (Installed Components key)
AND
NOT
the patch q323759 is installed (Installed Components key)
AND
NOT
the patch q328970 is installed (Installed Components key)
AND
NOT
the patch q324929 is installed (Installed Components key)
AND
NOT
the patch q810847 is installed (Installed Components key)
AND
NOT
the patch q813489 is installed (Installed Components key)
AND
NOT
the patch q818529 is installed (Installed Components key)
AND
NOT
the patch q822925 is installed (Installed Components key)
AND
NOT
the patch q828750 is installed (Installed Components key)
AND
NOT
the patch q824145 is installed (Installed Components key)
BACK