CVE-2001-0727

Internet Explorer 6.0 - Remote Code Execution via Header Field Manipulation

Title source: llm
STIX 2.1

Description

Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."

References (10)

Core 10
Core References
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2001-36.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=100835204509262&w=2
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A921
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7703
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/3033
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/m-027.shtml
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/443699
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3578
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=100861273114437&w=2

Scores

EPSS 0.3101
EPSS Percentile 98.1%

Details

Status published
Products (2)
microsoft/internet_explorer 5.5
microsoft/internet_explorer 6.0
Published Dec 14, 2001
Tracked Since Feb 18, 2026