Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.235
EPSS Ranking 95.7%