CVE-2002-0057
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 19%
exploitation probability
19%top 3% of all CVEs
observed exploitation
nono source reports it
XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
Affected products
n/a · n/aReferences
http://archives.neohapsis.com/archives/bugtraq/2001-12/0152.htmlhttp://marc.info/?l=bugtraq&m=101366383408821&w=2https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-008https://exchange.xforce.ibmcloud.com/vulnerabilities/7712http://www.osvdb.org/3032http://www.securityfocus.com/bid/3699