PT-2002-1312 · Microsoft · Internet Explorer
Published
2002-05-03
·
Updated
2021-07-23
·
CVE-2002-0242
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions prior to 7
Description
A cross-site scripting issue allows remote attackers to execute arbitrary script via an Extended HTML Form. The output from the remote server is not properly cleansed, enabling the execution of malicious scripts.
Recommendations
For versions prior to 7, update to a newer version to mitigate the risk. As a temporary workaround, consider disabling the use of Extended HTML Forms in Internet Explorer until a patch is available. Restrict access to untrusted websites to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer