Vulnerability Description
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Ie | 6.0 |
| Microsoft | Internet Explorer | 5.0 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=106979349517578&w=2
- http://marc.info/?l=bugtraq&m=107038202225587&w=2
- http://www.kb.cert.org/vuls/id/784102Third Party AdvisoryUS Government Resource
- http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu
- http://www.us-cert.gov/cas/techalerts/TA04-033A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-00
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13846
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://marc.info/?l=bugtraq&m=106979349517578&w=2
FAQ
What is CVE-2003-1026?
CVE-2003-1026 is a vulnerability with a CVSS score of 9.3 (HIGH). Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window...
How severe is CVE-2003-1026?
CVE-2003-1026 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-1026?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Ie, Microsoft Internet Explorer.