CVE-2000-0061
Internet Explorer 5 - Cross-Site Scripting via Security Zone Mismatch
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-0061.
AI-analyzed exploit summary This exploit leverages a security zone settings lag in Internet Explorer, allowing remote JavaScript to execute with local zone privileges. It uses a crafted HTML file to read local files by exploiting the delayed security zone update during document loading.
Description
Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.
Exploits (1)
This exploit leverages a security zone settings lag in Internet Explorer, allowing remote JavaScript to execute with local zone privileges. It uses a crafted HTML file to read local files by exploiting the delayed security zone update during document loading.