| Vulnerability Name: | CVE-2001-0092 (CCN-6086) | ||||||||
| Assigned: | 2000-12-01 | ||||||||
| Published: | 2000-12-01 | ||||||||
| Updated: | 2021-07-23 | ||||||||
| Summary: | A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability. | ||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2001-0092 Source: MITRE Type: CNA CVE-2001-0332 Source: CCN Type: Microsoft Security Bulletin MS00-033 Patch Available for "Frame Domain Verification", "Unauthorized Cookie Access", and "Malformed Component Attribute" Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS00-055 Patch Available for 'Scriptlet Rendering' Vulnerability Source: CCN Type: Microsoft Security Bulletin MS00-093 Patch Available for "Browser Print Template" and "File Upload via Form" Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS01-015 IE can Divulge Location of Cached Content Source: CCN Type: Microsoft Security Bulletin MS01-027 Flaws in Web Server Certificate Validation Could Enable Spoofing Source: OSVDB Type: UNKNOWN 7817 Source: CCN Type: OSVDB ID: 7817 Microsoft IE Frame Domain Validation Arbitrary File Access Source: CCN Type: BID-1636 Microsoft Internet Explorer Navigate Function Cross Frame Access Vulnerability Source: CCN Type: BID-2045 Microsoft Internet Explorer INPUT TYPE=FILE Vulnerability Source: MS Type: UNKNOWN MS00-093 Source: XF Type: UNKNOWN ie-frame-verification-read-files(6086) Source: XF Type: UNKNOWN ie-frame-verification-read-files(6086) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||