First published: Wed Dec 11 2002(Updated: )
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =5.0 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1187 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2002-1187, it is recommended to upgrade to a later, secure version of Internet Explorer.
CVE-2002-1187 affects Internet Explorer versions 5.0 through 6.0, including specific service packs.
The impact of CVE-2002-1187 allows attackers to exploit the vulnerability to read and execute files on the local system.
Users of Internet Explorer versions 5.0 to 6.0 are affected by CVE-2002-1187, particularly those who use frames or iframes.