First published: Sat Aug 24 2002(Updated: )
Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0723 is considered a critical vulnerability due to its potential to allow remote attackers to access sensitive files on the client system.
To fix CVE-2002-0723, apply the available security patches or update to a newer version of Microsoft Internet Explorer that is not affected.
CVE-2002-0723 affects Microsoft Internet Explorer versions 5.5 and 6.0.
Due to CVE-2002-0723, attackers can potentially read client files or execute arbitrary code on the affected system.
While CVE-2002-0723 is a historical vulnerability, it highlights the importance of keeping software updated to protect against similar modern vulnerabilities.