CVE-2002-0980

Internet Explorer 5.5-6.0 - Remote Code Execution via Web Folder Error Message Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0980. PoCs published by http-equiv.

AI-analyzed exploit summary This exploit leverages a vulnerability in Microsoft Outlook Express's MHTML URL handler to execute arbitrary script code in the Local Computer Zone by rendering a malicious .txt file. The PoC demonstrates script execution via an onload event and file navigation.

Description

The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.

Exploits (1)

exploitdb WORKING POC VERIFIED
by http-equiv · htmlremotewindows
https://www.exploit-db.com/exploits/21711

This exploit leverages a vulnerability in Microsoft Outlook Express's MHTML URL handler to execute arbitrary script code in the Local Computer Zone by rendering a malicious .txt file. The PoC demonstrates script execution via an onload event and file navigation.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Outlook Express (versions affected by CVE-2002-0980)
No auth needed
Prerequisites: Victim must open a malicious MHTML file or navigate to a crafted URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9881.php
Mailing List mailing-list x_refsource_vuln-dev
http://marc.info/?l=vuln-dev&m=102943486811091&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102942234427691&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5473
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=102937705527922&w=2

Scores

EPSS 0.2667
EPSS Percentile 97.8%

Details

Status published
Products (2)
microsoft/internet_explorer 5.5 (3 CPE variants)
microsoft/internet_explorer 6.0
Published Sep 24, 2002
Tracked Since Feb 18, 2026