peter bassill · operator
$ cve CVE-2000-0028 JSON

CVE-2000-0028 EXPLOIT

2.6
LOW · CVSS 2.0 · EPSS 23.1% (pctl 98)

Patch early

A public exploit exists.

Description

Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

Scoring

CVSS2.6 (LOW, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS23.13% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published1999-12-23
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftie
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD