| Vulnerability Name: | CVE-1999-0877 (CCN-3313) | ||||||||
| Assigned: | 1999-10-01 | ||||||||
| Published: | 1999-10-01 | ||||||||
| Updated: | 2021-07-22 | ||||||||
| Summary: | Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. | ||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-200 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-1999-0877 Source: MSKB Type: UNKNOWN Q243638 Source: CCN Type: Microsoft Download Web site "IFRAME ExecCommand" Vulnerability Source: CCN Type: Microsoft Security Bulletin MS99-042 Patch Available for 'IFRAME ExecCommand' Vulnerability Source: CCN Type: OSVDB ID: 7835 Microsoft IE IFRAME Document.ExecCommand Restriction Bypass Arbitrary File Access Source: CCN Type: BID-696 Microsoft IE5 IFRAME Vulnerability Source: MS Type: UNKNOWN MS99-042 Source: XF Type: UNKNOWN ie-iframe-exec(3313) Source: CCN Type: Microsoft Knowledge Base Article 243638 Update Available for "IFRAME Execcommand" Vulnerability in Internet Explorer 5 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||