CVE-2002-2062
Internet Explorer 5.5-6.0 - Cross-Site Scripting via FTP URL Hostname
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-2062. PoCs published by Eiji James Yoshida.
AI-analyzed exploit summary This exploit leverages a cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer's FTP folder view feature. By embedding malicious JavaScript in an FTP URL, an attacker can execute arbitrary code in the Local Computer context if specific settings are enabled.
Description
Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.
Exploits (1)
This exploit leverages a cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer's FTP folder view feature. By embedding malicious JavaScript in an FTP URL, an attacker can execute arbitrary code in the Local Computer context if specific settings are enabled.