Vulnerability Name: | CCN-18395 | ||||||
Published: | 2004-12-07 | ||||||
Updated: | 2004-12-07 | ||||||
Summary: | Microsoft Internet Explorer version 6.0 running on Microsoft Windows XP SP1 and Microsoft Windows 2000 SP4 could allow a remote attacker to obtain sensitive information. By creating a specially-crafted Web page that references the sysimage: URI handler in an image tag and contains the onError and onLoad events, a remote attacker could determine the existence of a file on the system, once the malicious Web page is visited. An attacker can then use this information to launch further attacks against the affected system. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Dec 07 2004 - 06:19:35 CST IE6 Vulnerability - Local File Detection Source: CCN Type: BID-11834 Microsoft Internet Explorer Sysimage Protocol Handler Local File Detection Vulnerability Source: XF Type: UNKNOWN ie-sysimage-obtain-info(18395) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |