CVE-2001-0091

Internet Explorer <5.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/7820
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6085

Scores

EPSS 0.0549
EPSS Percentile 92.0%

Details

Status published
Products (4)
microsoft/internet_explorer 4.0
microsoft/internet_explorer 5.0
microsoft/internet_explorer 5.01
microsoft/internet_explorer 5.5
Published Feb 16, 2001
Tracked Since Feb 18, 2026