vendor:
Internet Explorer
by:
Georgi Guninski
7.5
CVSS
HIGH
Cross-frame security bypass
352
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 4.x
Affected Version To: Internet Explorer 4.x and Internet Explorer 5.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
1999
Vulnerability in Internet Explorer 4.x and 5.5
Internet Explorer 4.x's implementation of Cross-frame security can be bypassed by appending '%01' to an arbitrary URL. This allows for the execution of arbitrary code on the target host, leading to access to local files, window spoofing, and arbitrary code execution. A variation of this vulnerability also exists in Microsoft Internet Explorer 5.5, where the ASCII equivalents of '^A' or '' can be used instead.
Mitigation:
Upgrade to a newer version of Internet Explorer or use an alternative web browser.