CVE-2002-1254
published 2002-12-11CVE-2002-1254: Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
50.76%
98.8th percentile
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit pattern involves opening a child window to a local/same-domain page, caching a reference to its document object or methods, then navigating the child window to a different domain/zone — monitor for cross-domain window manipulation via cached object references in IE 5.5/6.0 ↗
- →Exploit skeleton uses window.open() to a local HTML file followed by a location.href redirect to an external domain with a setTimeout callback to execute payload — look for this pattern in script blocks on untrusted pages ↗
- →Successful exploitation enables cookie theft, website impersonation, and local file disclosure/manipulation — correlate with unexpected cross-zone document access or anomalous file reads from IE process ↗
- ·Internet Explorer 6.0 with Service Pack 1 and Internet Explorer 5 with Service Pack 2 are reported as NOT vulnerable, though some reports indicate IE6 SP1 may still be affected ↗
- ·Vulnerability affects the cross-domain security model specifically via cached methods/objects — access control checks are absent when a document object is accessed through a separate cached reference ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=103530131201191&w=2http://security.greymagic.com/adv/gm012-ie/http://www.ciac.org/ciac/bulletins/n-018.shtmlhttp://www.iss.net/security_center/static/10435.phphttp://www.iss.net/security_center/static/10436.phphttp://www.iss.net/security_center/static/10437.phphttp://www.iss.net/security_center/static/10438.phphttp://www.iss.net/security_center/static/10439.phphttp://www.securityfocus.com/bid/6028https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066https://exchange.xforce.ibmcloud.com/vulnerabilities/10432https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A388https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A408http://marc.info/?l=bugtraq&m=103530131201191&w=2http://security.greymagic.com/adv/gm012-ie/http://www.ciac.org/ciac/bulletins/n-018.shtmlhttp://www.iss.net/security_center/static/10435.phphttp://www.iss.net/security_center/static/10436.phphttp://www.iss.net/security_center/static/10437.phphttp://www.iss.net/security_center/static/10438.phphttp://www.iss.net/security_center/static/10439.phphttp://www.securityfocus.com/bid/6028https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066https://exchange.xforce.ibmcloud.com/vulnerabilities/10432https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A388https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A408
2002-12-11
Published