Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-009 | vendor advisory |
http://www.osvdb.org/763 | vdb entry |
http://www.securityfocus.com/bid/4158 | vdb entry |
http://securitytracker.com/id?1003630 | vdb entry |