Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-0149

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2001-0149
Last Modified 05 Sep 2008 04:23:23
Published 02 Jun 2001 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2001-0149

Summary

Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.

Vulnerable Systems

Application

  • Microsoft Ie 5.5


References

MS - MS01-015

NTBUGTRAQ - 20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files

XF - ie-getobject-expose-files(5293)

BID - 1718


Last Updated: 27 May 2016 10:36:09