Vulnerability Name: | CVE-2002-0500 (CCN-8658) | ||||||||
Assigned: | 2002-03-27 | ||||||||
Published: | 2002-03-27 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20020326 Retrieving information on local files in IE (GM#003-IE) Source: CCN Type: BugTraq Mailing List, Mar 26 2002 - 18:21:56 CST Retrieving information on local files in IE (GM#003-IE) Source: MITRE Type: CNA CVE-2002-0500 Source: XF Type: Patch, Vendor Advisory ie-dynsrc-information-disclosure(8658) Source: CCN Type: OSVDB ID: 3036 Microsoft IE dynsrc File Information Leak Source: BID Type: Exploit, Vendor Advisory 4371 Source: CCN Type: BID-4371 Microsoft Internet Explorer DYNSRC File Information Disclosure Vulnerability Source: XF Type: UNKNOWN ie-dynsrc-information-disclosure(8658) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |