First published: Thu May 24 2001(Updated: )
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.01 | |
Internet Explorer | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0332 has a medium severity rating due to its capability to allow unauthorized access to local files.
To fix CVE-2001-0332, it is recommended to upgrade to a later version of Internet Explorer than 5.5.
CVE-2001-0332 affects Internet Explorer versions 5.01 and 5.5.
The impact of CVE-2001-0332 allows attackers to read certain files on a client computer through cross-domain frame manipulation.
There are no official workarounds for CVE-2001-0332; upgrading to a more secure version is the only recommended action.