Oval Definition:
oval:org.mitre.oval:def:543
Revision Date
:
2014-02-24
Version
:
44
Title
:
IE v6.0 (XP) Zone Restrictions Bypass via XML Vulnerability
Description
:
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2003-0817
Platform(s)
:
Microsoft Windows XP
Product(s)
:
Microsoft Internet Explorer
Definition Synopsis
Software section
Internet Explorer 6 is installed
AND
the version of mshtml.dll is less than 6.0.2734.1600
AND
NOT
the patch q824145 is installed (Installed Components key)
AND
Configuration section
ActiveX controls and active scripting are enabled
current user settings are being used and ActiveX controls and active scripting are enabled
NOT
use machine settings rather than individual user settings
AND
ActiveX controls are enabled for the current user
AND
active scripting is enabled for the current user
OR
local machine settings are being used and ActiveX controls and active scripting are enabled
use machine settings rather than individual user settings
AND
ActiveX controls are enabled for the local machine
AND
active scripting is enabled for the local machine
BACK