CVE
- Id
- 7640
- CVE No.
- CVE-2003-0816
- Status
- Candidate
- Description
- Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.
- Phase
- Assigned (20030918)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
45033 | 7640 | CVE-2003-0816 | BUGTRAQ:20030910 MSIE->NAFfileJPU | View |
45034 | 7640 | CVE-2003-0816 | URL:http://www.securityfocus.com/archive/1/336937 | View |
45035 | 7640 | CVE-2003-0816 | MISC:http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm | View |
45036 | 7640 | CVE-2003-0816 | BUGTRAQ:20030910 MSIE->WsOpenFileJPU | View |
45037 | 7640 | CVE-2003-0816 | URL:http://marc.info/?l=bugtraq&m=106321882821788&w=2 | View |
45038 | 7640 | CVE-2003-0816 | MISC:http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM | View |
45039 | 7640 | CVE-2003-0816 | BUGTRAQ:20030910 MSIE->WsBASEjpu | View |
45040 | 7640 | CVE-2003-0816 | URL:http://marc.info/?l=bugtraq&m=106322063729496&w=2 | View |
45041 | 7640 | CVE-2003-0816 | MISC:http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM | View |
45042 | 7640 | CVE-2003-0816 | BUGTRAQ:20030910 MSIE->WsFakeSrc | View |
45043 | 7640 | CVE-2003-0816 | URL:http://marc.info/?l=bugtraq&m=106321781819727&w=2 | View |
45044 | 7640 | CVE-2003-0816 | MISC:http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM | View |
45045 | 7640 | CVE-2003-0816 | BUGTRAQ:20030910 MSIE->WsOpenJpuInHistory | View |
45046 | 7640 | CVE-2003-0816 | URL:http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html | View |
45047 | 7640 | CVE-2003-0816 | MISC:http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM | View |
45048 | 7640 | CVE-2003-0816 | BUGTRAQ:20030910 MSIE->NAFjpuInHistory | View |
45049 | 7640 | CVE-2003-0816 | URL:http://marc.info/?l=bugtraq&m=106321693517858&w=2 | View |
45050 | 7640 | CVE-2003-0816 | MISC:http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM | View |
45051 | 7640 | CVE-2003-0816 | BUGTRAQ:20030910 MSIE->BackMyParent2:Multi-Thread version | View |
45052 | 7640 | CVE-2003-0816 | URL:http://marc.info/?l=bugtraq&m=106322240132721&w=2 | View |
45053 | 7640 | CVE-2003-0816 | MISC:http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM | View |
45054 | 7640 | CVE-2003-0816 | MISC:http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm | View |
45055 | 7640 | CVE-2003-0816 | BUGTRAQ:20030910 MSIE->RefBack | View |
45056 | 7640 | CVE-2003-0816 | URL:http://marc.info/?l=bugtraq&m=106321638416884&w=2 | View |
45057 | 7640 | CVE-2003-0816 | MISC:http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM | View |
45058 | 7640 | CVE-2003-0816 | BUGTRAQ:20030911 LiuDieYu"s missing files are here. | View |
45059 | 7640 | CVE-2003-0816 | URL:http://www.securityfocus.com/archive/1/337086 | View |
45060 | 7640 | CVE-2003-0816 | MS:MS03-048 | View |
45061 | 7640 | CVE-2003-0816 | URL:http://www.microsoft.com/technet/security/bulletin/ms03-048.asp | View |
45062 | 7640 | CVE-2003-0816 | CERT-VN:VU#771604 | View |
45063 | 7640 | CVE-2003-0816 | URL:http://www.kb.cert.org/vuls/id/771604 | View |
45064 | 7640 | CVE-2003-0816 | CERT-VN:VU#652452 | View |
45065 | 7640 | CVE-2003-0816 | URL:http://www.kb.cert.org/vuls/id/652452 | View |
45066 | 7640 | CVE-2003-0816 | OVAL:oval:org.mitre.oval:def:361 | View |
45067 | 7640 | CVE-2003-0816 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:361 | View |
45068 | 7640 | CVE-2003-0816 | OVAL:oval:org.mitre.oval:def:362 | View |
45069 | 7640 | CVE-2003-0816 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:362 | View |
45070 | 7640 | CVE-2003-0816 | OVAL:oval:org.mitre.oval:def:363 | View |
45071 | 7640 | CVE-2003-0816 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:363 | View |
45072 | 7640 | CVE-2003-0816 | OVAL:oval:org.mitre.oval:def:409 | View |
45073 | 7640 | CVE-2003-0816 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:409 | View |
45074 | 7640 | CVE-2003-0816 | OVAL:oval:org.mitre.oval:def:416 | View |
45075 | 7640 | CVE-2003-0816 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:416 | View |
45076 | 7640 | CVE-2003-0816 | OVAL:oval:org.mitre.oval:def:459 | View |
45077 | 7640 | CVE-2003-0816 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:459 | View |
45078 | 7640 | CVE-2003-0816 | OVAL:oval:org.mitre.oval:def:479 | View |
45079 | 7640 | CVE-2003-0816 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:479 | View |
45080 | 7640 | CVE-2003-0816 | SECTRACK:1007687 | View |
45081 | 7640 | CVE-2003-0816 | URL:http://securitytracker.com/id?1007687 | View |
45082 | 7640 | CVE-2003-0816 | SECUNIA:10192 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
63610 | JVNDB-2003-000336 | Microsoft Internet Explorer の XML オブジェクトにおける情報漏洩の脆弱性 | Microsoft Internet Explorer にはコンテンツを XML データにバインドする際に、取り扱うパスの妥当性の確認を適切に行わない脆弱性が存在します。 | CVE-2003-0817 | 7640 | 7.5 | http://jvndb.jvn.jp/ja/contents/2003/JVNDB-2003-000336.html | View |