CVE-2003-1328

Microsoft Internet Explorer <6.0 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-1328. PoCs published by Andreas Sandblad.

AI-analyzed exploit summary The exploit leverages the showHelp() function in Microsoft Internet Explorer to execute arbitrary JavaScript, read local files, and run system commands via pluggable protocols. It demonstrates multiple attack vectors including cookie theft, file disclosure, and command execution.

Description

The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Andreas Sandblad · textremotewindows
https://www.exploit-db.com/exploits/22226

The exploit leverages the showHelp() function in Microsoft Internet Explorer to execute arbitrary JavaScript, read local files, and run system commands via pluggable protocols. It demonstrates multiple attack vectors including cookie theft, file disclosure, and command execution.

Classification
Working Poc 95%
Attack Type
Rce | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer (versions affected by CVE-2003-1328)
No auth needed
Prerequisites: Victim must visit a malicious webpage or execute the provided JavaScript in a vulnerable version of Internet Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A57
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/n-038.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6780
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/400577
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2003-02/0083.html
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/11259.php

Scores

EPSS 0.3893
EPSS Percentile 98.4%

Details

Status published
Products (4)
microsoft/ie 6.0 sp1
microsoft/internet_explorer 5.0.1 (4 CPE variants)
microsoft/internet_explorer 5.5 (3 CPE variants)
microsoft/internet_explorer 6.0
Published Feb 19, 2003
Tracked Since Feb 18, 2026