Back
CVE-2002-0027
Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874.
Published: Mar 8, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 6.0 |
GitHub Security Advisory GHSA-56vq-gj2v-q82q
Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in...
References (10)
- http://www.osvdb.org/3031
- http://www.securityfocus.com/archive/1/246522 Vendor Advisory
- http://www.securityfocus.com/bid/3721 Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-005
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A974
- http://www.osvdb.org/3031
- http://www.securityfocus.com/archive/1/246522 Vendor Advisory
- http://www.securityfocus.com/bid/3721 Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-005
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A974
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
19.32%
Top 3% most likely to be exploited
Threat Score
35.8 / 100
Data Sources
NVD
EPSS
GitHub