20020606 Microsoft Internet Explorermailing list
http://archives.neohapsis.com/archives/bugtraq/2002-06/0037.html CVE-2002-2062
Microsoft Internet Explorer 5/6 - FTP Web View Cross-Site Scripting
Record summary
CVE-2002-2062 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Internet Explorer 5/6 - FTP Web View Cross-Site ScriptingExploitDB exploitby Eiji James YoshidaNot analyzed1 file
References
5geocities.co.jp
http://www.geocities.co.jp/SiliconValley/1667/advisory02e.html ie-ftp-name-xss(9290)vdb entry
http://www.iss.net/security_center/static/9290.php 4954vdb entry
http://www.securityfocus.com/bid/4954 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-2062