CVE-2002-1188

Internet Explorer <6.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6217
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A690
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A444
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/n-018.shtml
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10665.php
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103184415307193&w=2

Scores

EPSS 0.1229
EPSS Percentile 95.8%

Details

Status published
Products (3)
microsoft/internet_explorer 5.0.1 (3 CPE variants)
microsoft/internet_explorer 5.5 (3 CPE variants)
microsoft/internet_explorer 6.0
Published Dec 11, 2002
Tracked Since Feb 18, 2026