Vulnerability Name:

CVE-2000-0465 (CCN-4500)

Assigned:2000-05-17
Published:2000-05-17
Updated:2021-07-23
Summary:Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: MITRE
Type: CNA
CVE-2000-0465

Source: CCN
Type: CIAC Information Bulletin K-044
Microsoft: Vulnerabilities in Internet Explorer

Source: CCN
Type: Microsoft Security Bulletin MS00-033
Patch Available for "Frame Domain Verification", "Unauthorized Cookie Access", and "Malformed Component Attribute" Vulnerabilities

Source: MSKB
Type: UNKNOWN
Q251108

Source: MSKB
Type: UNKNOWN
Q255676

Source: CCN
Type: OSVDB ID: 1342
Microsoft IE DocumentComplete() Cross Frame Access

Source: BID
Type: UNKNOWN
1224

Source: CCN
Type: BID-1224
Microsoft IE DocumentComplete() Cross Frame Access Vulnerability

Source: MS
Type: UNKNOWN
MS00-033

Source: XF
Type: UNKNOWN
ie-frame-domain-verification(4500)

Source: CCN
Type: Microsoft Knowledge Base Article 251108
Update Available for the "Frame Domain Verification" Issue

Source: CCN
Type: Microsoft Knowledge Base Article 255676
DocumentComplete on IFRAME May Cause Cross-Domain Security Issues

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:preview:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:4.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft internet explorer 5.0
    microsoft internet explorer 5.01
    microsoft internet explorer 5.5 preview
    microsoft internet explorer 4.0
    microsoft ie 4.0
    microsoft ie 4.0.1
    microsoft ie 5.0
    microsoft ie 5.01