Vulnerability Name:
CVE-2000-0768 (CCN-5504)
Assigned:
2000-08-09
Published:
2000-08-09
Updated:
2021-07-23
Summary:
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.
CVSS v3 Severity:
3.7 Low
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
None
Availibility (A):
None
CVSS v2 Severity:
2.6 Low
(CVSS v2 Vector:
AV:N/AC:H/Au:N/C:P/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
2.6 Low
(CCN CVSS v2 Vector:
AV:N/AC:H/Au:N/C:P/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Gain Access
References:
Source: CCN
Type: BugTraq Mailing List, Tue Jun 06 2000 - 07:31:47 CDT
IE 5 Cross-frame security vulnerability using IFRAME and WebBrowser control
Source: MITRE
Type: CNA
CVE-2000-0503
Source: MITRE
Type: CNA
CVE-2000-0768
Source: CCN
Type: Microsoft Security Bulletin MS00-033
Patch Available for "Frame Domain Verification", "Unauthorized Cookie Access", and "Malformed Component Attribute" Vulnerabilities
Source: CCN
Type: Microsoft Security Bulletin MS00-055
Patch Available for "Scriptlet Rendering" Vulnerability
Source: CCN
Type: OSVDB ID: 7825
Microsoft IE Domain Frame Arbitrary File Access
Source: CCN
Type: BID-1311
Microsoft IE NavigateComplete2 Cross Frame Access Vulnerability
Source: BID
Type: Patch, Vendor Advisory
1564
Source: CCN
Type: BID-1564
Microsoft Internet Explorer Scriptlet Rendering Vulnerability
Source: MS
Type: UNKNOWN
MS00-055
Source: XF
Type: UNKNOWN
ie-frame-domain-file-access(5504)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:microsoft:ie:4.0:*:windows_98:*:*:*:*:*
OR
cpe:/a:microsoft:ie:4.0:*:windows_nt:*:*:*:*:*
OR
cpe:/a:microsoft:ie:5.0:*:windows:*:*:*:*:*
OR
cpe:/a:microsoft:ie:5.0:*:windows_2000:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:ie:5.0:*:windows_95:*:*:*:*:*
OR
cpe:/a:microsoft:ie:5.0:*:windows_98:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:4.0.1:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:4.0.1:sp1:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:4.0.1:sp2:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.5:preview:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.5:-:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.1:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.0.1:-:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
microsoft
ie 4.0
microsoft
ie 4.0
microsoft
ie 5.0
microsoft
ie 5.0
microsoft
internet explorer 4.0
microsoft
internet explorer 5.01
microsoft
internet explorer 5.5
microsoft
ie 5.0
microsoft
ie 5.0
microsoft
ie 4.0
microsoft
ie 4.0.1
microsoft
ie 4.0.1 sp1
microsoft
ie 5.0
microsoft
ie 4.0.1 sp2
microsoft
ie 5.5 preview
microsoft
ie 5.5
microsoft
ie 5.5 sp1
microsoft
ie 5.1
microsoft
ie 5.5 sp2
microsoft
ie 5.0.1
microsoft
ie 5.0.1 sp1
microsoft
ie 5.0.1 sp2
microsoft
ie 5.0.1 sp3
microsoft
ie 5.0.1 sp4