First published: Wed May 17 2000(Updated: )
Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =4.0 | |
Internet Explorer | =5.0 | |
Internet Explorer | =5.01 | |
Internet Explorer | =5.5-preview |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0465 is considered a moderate severity vulnerability due to its potential for exposing sensitive client files.
To fix CVE-2000-0465, users should upgrade to the latest version of Internet Explorer that is not vulnerable to this issue.
CVE-2000-0465 affects Internet Explorer versions 4.0, 5.0, 5.01, and the 5.5 preview.
CVE-2000-0465 allows remote attackers to read client files through improper frame domain verification.
A recommended workaround for CVE-2000-0465 is to avoid using vulnerable versions of Internet Explorer and to utilize other web browsers.