Back

CVE-2002-1217

Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.

Published: Oct 28, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-vvg3-w575-g5c9

Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 49.81%

Top 1% most likely to be exploited

Threat Score 44.9 / 100

Data Sources

NVD EPSS GitHub