vendor:
Internet Explorer
by:
SecurityFocus
7.5
CVSS
HIGH
Access control vulnerability
284
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 5.5
Affected Version To: Internet Explorer 6.0
Patch Exists: YES
Related CWE: CVE-2002-0392
CPE: a:microsoft:internet_explorer
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Multiple vulnerabilities in Microsoft Internet Explorer
The vulnerabilities are due to how Internet Explorer handles cached objects. This vulnerability may allow remote attackers to execute script code in the context of other domains and security zones. Exploitation of this vulnerability may allow for theft of cookie information, website impersonation or disclosure and manipulation of local files.
Mitigation:
Upgrade to the latest version of Internet Explorer