First published: Tue Jun 11 2002(Updated: )
Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =5.0 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0500 has a moderate severity rating, as it allows remote attackers to infer the existence of files on a victim's system.
CVE-2002-0500 exploits the IMG tag with a dynsrc property to reveal file information based on specified files.
CVE-2002-0500 affects Internet Explorer versions 5.0 through 6.0, including specific service packs.
To mitigate risks from CVE-2002-0500, users should upgrade to newer and supported versions of Internet Explorer.
There is no specific patch for CVE-2002-0500, but upgrading to a newer version of Internet Explorer will resolve the issue.