Vulnerability Details CVE-2001-0332
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.181
EPSS Ranking 94.9%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2001-0332
-
cpe:2.3:a:microsoft:internet_explorer:5.01
-
cpe:2.3:a:microsoft:internet_explorer:5.5