Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2003-1026
Description:Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2003-1026
Bugtraq: 20031125 BackToFramedJpu - a successor of BackToJpu attack (Google Search)
http://marc.info/?l=bugtraq&m=106979349517578&w=2
Bugtraq: 20031201 Comments on 5 IE vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=107038202225587&w=2
Cert/CC Advisory: TA04-033A
http://www.us-cert.gov/cas/techalerts/TA04-033A.html
CERT/CC vulnerability note: VU#784102
http://www.kb.cert.org/vuls/id/784102
http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu
Microsoft Security Bulletin: MS04-004
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A630
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A643
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A687
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A689
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A745
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A774
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A805
XForce ISS Database: ie-subframe-xss(13846)
https://exchange.xforce.ibmcloud.com/vulnerabilities/13846




© 1998-2025 E-Soft Inc. All rights reserved.