CVE-2001-0332

Internet Explorer <5.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=98609031517525&w=2

Scores

EPSS 0.0570
EPSS Percentile 92.3%

Details

Status published
Products (2)
microsoft/internet_explorer 5.01
microsoft/internet_explorer 5.5
Published Jun 27, 2001
Tracked Since Feb 18, 2026