Back

CVE-2002-0078

The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.

Published: Mar 29, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-rh9r-xpf4-gh2j

The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 21.95%

Top 3% most likely to be exploited

Threat Score 36.6 / 100

Data Sources

NVD EPSS GitHub