CVE-2003-0446

Internet Explorer 5.5 and 6.0 - Cross-Site Scripting via XML Parse Error

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0446. PoCs published by GreyMagic Software.

AI-analyzed exploit summary This is a writeup describing a cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer when parsing XML files with the MSXML parser. The vulnerability allows execution of script code if malicious HTML is included in the URL of an unparsable XML file.

Description

Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.

Exploits (1)

exploitdb WRITEUP VERIFIED
by GreyMagic Software · textremotewindows
https://www.exploit-db.com/exploits/22783

This is a writeup describing a cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer when parsing XML files with the MSXML parser. The vulnerability allows execution of script code if malicious HTML is included in the URL of an unparsable XML file.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer (versions affected by CVE-2003-0446)
No auth needed
Prerequisites: A web server hosting an unparsable XML file · Victim using a vulnerable version of Internet Explorer
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/12334
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105595990924165&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/3065
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=105585001905002&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/7938
Exploit, Vendor Advisory x_refsource_misc
http://security.greymagic.com/adv/gm013-ie/
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105585986015421&w=2
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2003-06/0120.html
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005762.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/9055

Scores

EPSS 0.2300
EPSS Percentile 97.5%

Details

Status published
Products (2)
microsoft/internet_explorer 5.5
microsoft/internet_explorer 6.0
Published Jul 24, 2003
Tracked Since Feb 18, 2026