CVE-2003-0116

Microsoft Internet Explorer <6.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/301945
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/244729
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6306

Scores

EPSS 0.2525
EPSS Percentile 97.7%

Details

Status published
Products (4)
microsoft/ie 6.0 sp1
microsoft/internet_explorer 5.0.1 (4 CPE variants)
microsoft/internet_explorer 5.5 (3 CPE variants)
microsoft/internet_explorer 6.0
Published May 12, 2003
Tracked Since Feb 18, 2026