First published: Fri Oct 13 2000(Updated: )
The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =4.0 | |
Internet Explorer | =5.0 | |
Internet Explorer | =5.01 | |
Internet Explorer | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0767 has a severity rating that indicates a medium risk due to the potential for unauthorized file access.
CVE-2000-0767 affects Internet Explorer versions 4.x and 5.x, allowing attackers to read arbitrary files on the user's system.
To mitigate CVE-2000-0767, users should upgrade to a newer version of Internet Explorer that is not affected by this vulnerability.
Yes, CVE-2000-0767 is a well-documented vulnerability that has been recognized for its potential impact on file security.
CVE-2000-0767 can be exploited through specially crafted web pages that invoke the vulnerable ActiveX control to access local files.