peter bassill · operator
$ cve CVE-2002-0193 JSON

CVE-2002-0193 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 33.3% (pctl 98)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS33.34% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2002-05-29
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD