CVE-2003-0447

Internet Explorer <6.0 - XSS

Title source: llm
STIX 2.1

Description

The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.

Exploits (1)

exploitdb WORKING POC VERIFIED
by GreyMagic Software · textremotewindows
https://www.exploit-db.com/exploits/22784

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105585933614773&w=2
Exploit, Vendor Advisory x_refsource_misc
http://security.greymagic.com/adv/gm014-ie/
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=105585142406147&w=2
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005763.html

Scores

EPSS 0.3253
EPSS Percentile 96.9%

Details

Status published
Products (3)
microsoft/internet_explorer 5.01
microsoft/internet_explorer 5.5
microsoft/internet_explorer 6.0
Published Jul 24, 2003
Tracked Since Feb 18, 2026