CVE-2003-0115

Microsoft Internet Explorer <6.0 - XSS

Title source: llm
STIX 2.1

Description

Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.

References (2)

Core 2
Core References
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/11848.php

Scores

EPSS 0.1158
EPSS Percentile 95.6%

Details

Status published
Products (4)
microsoft/ie 6.0 sp1
microsoft/internet_explorer 5.0.1 (4 CPE variants)
microsoft/internet_explorer 5.5 (3 CPE variants)
microsoft/internet_explorer 6.0
Published May 12, 2003
Tracked Since Feb 18, 2026