vendor:
Internet Explorer
by:
Cheng Peng Su
8.3
CVSS
HIGH
Cross-Zone Scripting
79
CWE
Product Name: Internet Explorer
Affected Version From: Microsoft Internet Explorer 5.0
Affected Version To: Microsoft Internet Explorer 6.0
Patch Exists: YES
Related CWE: CVE-2002-0649
CPE: a:microsoft:internet_explorer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Cross-Zone Scripting Vulnerability in Microsoft Internet Explorer
Cross-Zone Scripting is a vulnerability in Microsoft Internet Explorer that allows malicious scripts and Active Content to access document properties across different Security Zones and foreign domains. This vulnerability is exposed when search panes are opened via the window.open method. It is possible for malicious script code to access the properties of a foreign domain opened within the search pane. An example of this vulnerability is demonstrated in the code snippets provided, where a malicious script is used to create a file on the user's desktop.
Mitigation:
Microsoft has released a patch to address this issue.