| Vulnerability Name: | CVE-2001-0148 (CCN-6227) | ||||||||
| Assigned: | 2001-01-01 | ||||||||
| Published: | 2001-01-01 | ||||||||
| Updated: | 2018-10-12 | ||||||||
| Summary: | The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: BUGTRAQ Type: Exploit, Patch, Vendor Advisory 20010101 Windows Media Player 7 and IE vulnerability - executing arbitrary programs Source: MITRE Type: CNA CVE-2001-0148 Source: CCN Type: CIAC Information Bulletin L-061 Microsoft IE can Divulge Location of Cached Content Source: CCN Type: Georgi Guninski Security Advisory #31 Windows Media Player 7 and IE vulnerability - executing arbitrary programs Source: CCN Type: US-CERT VU#879920 Microsoft Windows Media Player ActiveX control allows execution of javascript in already open frames Source: CCN Type: Microsoft Security Bulletin MS00-033 Patch Available for "Frame Domain Verification", "Unauthorized Cookie Access", and "Malformed Component Attribute" Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS00-055 Patch Available for 'Scriptlet Rendering' Vulnerability Source: CCN Type: Microsoft Security Bulletin MS00-093 Patch Available for "Browser Print Template" and "File Upload via Form" Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS01-015 IE can Divulge Location of Cached Content Source: CCN Type: Microsoft Security Bulletin MS01-027 Flaws in Web Server Certificate Validation Could Enable Spoofing Source: CCN Type: OSVDB ID: 7178 Microsoft Windows Media Player WMP ActiveX Control Javascript Command Execution Source: CCN Type: BID-1636 Microsoft Internet Explorer Navigate Function Cross Frame Access Vulnerability Source: CCN Type: BID-2167 Microsoft Windows Media Player Javascript URL Vulnerability Source: MS Type: UNKNOWN MS01-015 Source: XF Type: UNKNOWN media-player-execute-commands(6227) Source: XF Type: UNKNOWN media-player-execute-commands(6227) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||