PT-2004-1204 · Microsoft · Internet Explorer

Andreas Sandblad

·

Published

2004-01-08

·

Updated

2021-07-23

·

CVE-2003-1026

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Internet Explorer versions 5.01 through 6 SP1
Description The issue allows remote attackers to bypass zone restrictions. This is achieved via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back() function is called.
Recommendations For Internet Explorer versions 5.01 through 6 SP1, consider disabling javascript execution in sub-frames as a temporary workaround until a patch is available. Restrict access to sensitive zones to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2003-1026

Affected Products

Internet Explorer