First published: Tue Dec 31 2002(Updated: )
Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2062 is considered a medium severity vulnerability due to its ability to allow cross-site scripting (XSS) attacks.
To fix CVE-2002-2062, users should upgrade to a later version of Internet Explorer that does not have this vulnerability.
CVE-2002-2062 affects Internet Explorer versions 5.5 and 6.0 on Windows 2000 with specific settings enabled.
Exploiting CVE-2002-2062 allows attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or session hijacking.
While CVE-2002-2062 is less of a concern today due to outdated software, any users still running affected versions may be at risk.