PT-2002-1126 · Microsoft · Internet Explorer
Published
2002-03-08
·
Updated
2021-07-23
·
CVE-2002-0024
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 5.01 through 6.0
Description
The issue allows an attacker to manipulate the display of a file's name by using the Content-Disposition and Content-Type HTML header fields. This could deceive a user into thinking a file is safe to download.
Recommendations
For Internet Explorer versions 5.01 through 6.0, consider avoiding downloads from untrusted sources until a fix is available. As a temporary workaround, users should be cautious when downloading files and verify the file type and source before opening them.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer