CVE Vulnerabilities

CVE-2002-0057

Published: Mar 08, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.

Affected Software

NameVendorStart VersionEnd Version
Internet_explorerMicrosoft6.0 (including)6.0 (including)
Sql_serverMicrosoft2000 (including)2000 (including)
Sql_serverMicrosoft2000-sp1 (including)2000-sp1 (including)
Sql_serverMicrosoft2000-sp2 (including)2000-sp2 (including)
Xml_core_servicesMicrosoft2.6 (including)2.6 (including)
Xml_core_servicesMicrosoft3.0 (including)3.0 (including)
Xml_core_servicesMicrosoft4.0 (including)4.0 (including)

References