CVE-2003-0116 Information

Description

Microsoft Internet Explorer 5.01 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files aka \Modal Dialog script execution.\

Reference

http://www.kb.cert.org/vuls/id/244729 http://www.securityfocus.com/archive/1/301945 http://www.securityfocus.com/bid/6306 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015

Share on: