CVE-2002-0723

Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."

Scoring

CVSS base score
0.88
EPSS probability
21.93%
Published
2002-08-24
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs