First published: Thu May 24 2001(Updated: )
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.01 | |
Internet Explorer | <=5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0246 has a critical severity rating due to its potential to allow unauthorized access to local files.
To fix CVE-2001-0246, upgrade to a later version of Internet Explorer that is not affected by this vulnerability.
CVE-2001-0246 affects Internet Explorer versions up to and including 5.5 and also 5.01.
CVE-2001-0246 allows remote attackers to read local files by exploiting domain verification issues in frames.
CVE-2001-0246 is primarily a concern for legacy systems still using Internet Explorer 5.5 or earlier.