CVE
- Id
- 3067
- CVE No.
- CVE-2001-0246
- Status
- Candidate
- Description
- Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.
- Phase
- Proposed (20010524)
- Votes
- ACCEPT(5) Baker, Cole, Magdych, Wall, Williams | MODIFY(1) Frech | NOOP(2) Renaud, Ziese | REVIEWING(1) Christey
- Comments
- Christey> See comments for CVE-2001-0332; may need to be merged because | of CD:SF-LOC. | Frech> XF:ie-frame-verification-variant(6748)