← Back

CVE-2001-0332

nvd nist
Published: Jun 27, 2001Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.

Affected (2)

1 product
Internet Explorer
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 5.01
Version 5.5

Timeline

No history available yet.