CVE-2000-0156

Internet Explorer <5.x - SSRF

Title source: llm
STIX 2.1

Description

Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Georgi Guninski · textremotewindows
https://www.exploit-db.com/exploits/19719

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/3996
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/7827

Scores

EPSS 0.1747
EPSS Percentile 95.1%

Details

Status published
Products (4)
microsoft/internet_explorer 4.0
microsoft/internet_explorer 4.0.1
microsoft/internet_explorer 5.0
microsoft/internet_explorer 5.01
Published Feb 16, 2000
Tracked Since Feb 18, 2026