Vulnerability Name:

CVE-2002-0980 (CCN-9881)

Assigned:2002-08-15
Published:2002-08-15
Updated:2021-07-23
Summary:The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Wed Aug 14 2002 - 19:34:17 CDT
SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0

Source: MITRE
Type: CNA
CVE-2002-0980

Source: BUGTRAQ
Type: UNKNOWN
20020815 SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0

Source: NTBUGTRAQ
Type: UNKNOWN
20020815 SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0

Source: VULN-DEV
Type: UNKNOWN
20020815 SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0

Source: CCN
Type: CIAC Information Bulletin N-081
Microsoft Cumulative Patch for Outlook Express

Source: XF
Type: UNKNOWN
ie-webfolder-script-injection(9881)

Source: CCN
Type: US-CERT VU#208052
Microsoft Internet Explorer and Outlook Express MHTML rendering engine incorrectly executes script in Local Computer Zone

Source: CCN
Type: Microsoft Security Bulletin MS03-014
Cumulative Patch for Outlook Express (330994)

Source: CCN
Type: Microsoft Security Bulletin MS04-013
Cumulative Security Update for Outlook Express (837009)

Source: CCN
Type: Microsoft Security Bulletin MS04-018
Cumulative Security Update for Outlook Express (823353)

Source: CCN
Type: Microsoft Security Bulletin MS06-016
Cumulative Security Update for Outlook Express (911567)

Source: CCN
Type: Microsoft Security Bulletin MS06-076
Cumulative Security Update for Outlook Express (923694)

Source: CCN
Type: Microsoft Security Bulletin MS07-034
Cumulative Security Update for Outlook Express and Windows Mail (929123)

Source: CCN
Type: Microsoft Security Bulletin MS07-056
Security Update for Outlook Express and Windows Mail (941202)

Source: CCN
Type: Microsoft Security Bulletin MS08-048
Security Update for Outlook Express and Windows Mail (951066)

Source: CCN
Type: Microsoft Security Bulletin MS10-030
Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution (978542)

Source: CCN
Type: OSVDB ID: 3053
Microsoft IE Web Folder Script Injection

Source: BID
Type: UNKNOWN
5473

Source: CCN
Type: BID-5473
Microsoft Outlook Express MHTML URL Handler File Rendering Vulnerability

Source: MS
Type: UNKNOWN
MS03-014

Source: XF
Type: UNKNOWN
ie-webfolder-script-injection(9881)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:-:*:*:*:*:*:*
  • OR cpe:/a:microsoft:outlook_express:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:microsoft:outlook_express:5.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft internet explorer 5.5
    microsoft internet explorer 5.5 sp1
    microsoft internet explorer 5.5 sp2
    microsoft internet explorer 6.0
    microsoft ie 5.0
    microsoft ie 5.5
    microsoft outlook express 6.0
    microsoft ie 6.0
    microsoft outlook express 5.5