First published: Tue Apr 18 2000(Updated: )
Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.0 | |
Internet Explorer | =5.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0266 is categorized as a moderate severity vulnerability.
CVE-2000-0266 allows remote attackers to bypass the cross frame security policy in Internet Explorer 5.0 and 5.01.
Exploitation of CVE-2000-0266 can lead to unauthorized access to manipulate the Document Object Model (DOM) through arbitrary JavaScript URLs.
No official patch is available for CVE-2000-0266 due to its age, but upgrading to a newer version of Internet Explorer is recommended.
CVE-2000-0266 affects Internet Explorer versions 5.0 and 5.01.