CVE-2003-1026

Scores

EPSS

0.558medium55.8%
0%20%40%60%80%100%

Percentile: 55.8%

CVSS

9.3critical2.0
0246810

CVSS Score: 9.3/10

All CVSS Scores

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window’s zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the “Travel Log Cross Domain Vulnerability.”

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-264

Exploits

Exploit ID: 151

Source: exploitdb

URL: https://www.exploit-db.com/exploits/151

Vulnerable Software (2)

Type: Configuration

Vendor: *

Product: ie

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:...

Source: nvd

Type: Configuration

Vendor: *

Product: internet_explorer

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:...

Source: nvd

End of list