CVE-2002-0648: Medium severity Microsoft Internet Explorer vulnerability
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0648?
CVE-2002-0648 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2002-0648?
To mitigate CVE-2002-0648, users should upgrade to a newer version of Internet Explorer that does not have this vulnerability.
What impact can CVE-2002-0648 have on my system?
CVE-2002-0648 could allow remote attackers to read arbitrary files from the affected system, leading to disclosure of sensitive information.
Which versions of Internet Explorer are affected by CVE-2002-0648?
CVE-2002-0648 affects Microsoft Internet Explorer versions 5.01, 5.5, and 6.0.
Is CVE-2002-0648 still a concern today?
Although CVE-2002-0648 is relatively old, users running unsupported versions of Internet Explorer should be aware of its potential risks.