Back

CVE-2001-0727

Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."

Published: Dec 14, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-93xq-2hp2-cg7q

Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 31.01%

Top 2% most likely to be exploited

Threat Score 39.3 / 100

Data Sources

NVD EPSS GitHub