CVE-2002-0057

XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.

Scoring

CVSS base score
1.67
EPSS probability
41.76%
Published
2002-06-25
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs