← Back

CVE-2002-2311

nvd nist
Published: Dec 31, 2002Modified: Apr 16, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the vendor has disputed the severity of this issue.

Affected (9)

1 product
Internet Explorer
Opera Web Browser
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 5.0.1
Version 5.0
Version 5.5
Version 5.5 sp1
Version 5.5 sp2
Version 6.0
Opera Software
Version 6.0.1
Version 6.0.1
Version 6.0.1

Related CWEs

References (8)

Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.