Oval Definition:oval:org.mitre.oval:def:974
Revision Date:2016-02-19Version:46
Title:IE Frame Domain Verification Vulnerability
Description:Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2002-0027
Platform(s):Microsoft Windows 2000
Microsoft Windows 98
Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows XP
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • Microsoft Internet Explorer 6 is installed
  • AND File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100
  • AND NOT the patch q316059 is installed (Installed Components key)
  • AND NOT the patch q319282 is installed (Installed Components key)
  • AND NOT the patch q321232 is installed (Installed Components key)
  • AND NOT the patch q323759 is installed (Installed Components key)
  • AND NOT the patch q328970 is installed (Installed Components key)
  • AND NOT the patch q324929 is installed (Installed Components key)
  • AND NOT the patch q810847 is installed (Installed Components key)
  • AND NOT the patch q813489 is installed (Installed Components key)
  • AND NOT the patch q818529 is installed (Installed Components key)
  • AND NOT the patch q822925 is installed (Installed Components key)
  • AND NOT the patch q828750 is installed (Installed Components key)
  • AND NOT the patch q824145 is installed (Installed Components key)
  • AND NOT the patch q832894 is installed (Installed Components key)
  • BACK