[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2003-1026Date: (C)2004-01-20   (M)2023-12-22


Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://marc.info/?l=bugtraq&m=106979349517578&w=2
http://marc.info/?l=bugtraq&m=107038202225587&w=2
MS04-004
TA04-033A
VU#784102
http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu
ie-subframe-xss(13846)
oval:org.mitre.oval:def:630
oval:org.mitre.oval:def:643
oval:org.mitre.oval:def:687
oval:org.mitre.oval:def:689
oval:org.mitre.oval:def:745
oval:org.mitre.oval:def:774
oval:org.mitre.oval:def:805

CWE    1
CWE-264
OVAL    7
oval:org.mitre.oval:def:774
oval:org.mitre.oval:def:687
oval:org.mitre.oval:def:643
oval:org.mitre.oval:def:689
...

© SecPod Technologies