CVE-2002-0980
Internet Explorer <6.0 - RCE
Title source: llmDescription
The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by http-equiv · htmlremotewindows
https://www.exploit-db.com/exploits/21711
References (6)
Scores
EPSS
0.4045
EPSS Percentile
97.4%
Details
Status
published
Products (2)
microsoft/internet_explorer
5.5 (3 CPE variants)
microsoft/internet_explorer
6.0
Published
Sep 24, 2002
Tracked Since
Feb 18, 2026