CVE-2002-0500Microsoft Internet Explorer vulnerability

2 documents2 sources
Severity
5.0MEDIUMNVD
EPSS
20.4%
top 4.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateApr 30

Description

Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmicrosoft/internet_explorer4 versions+3

Patches

🔴Vulnerability Details

1
GHSA
GHSA-5v65-cw5f-3jfp: Internet Explorer 52022-04-30
CVE-2002-0500 — Microsoft vulnerability | cvebase