CVE-2000-0266

Internet Explorer 5.01 - Cross-Frame Security Policy Bypass via Malicious Applet

Title source: llm
STIX 2.1

Description

Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1121
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=38FC6130.D6D178FD%40nat.bg

Scores

EPSS 0.1623
EPSS Percentile 96.6%

Details

Status published
Products (2)
microsoft/internet_explorer 5.0
microsoft/internet_explorer 5.01
Published Apr 18, 2000
Tracked Since Feb 18, 2026