peter bassill · operator
$ cve CVE-2003-0447 JSON

CVE-2003-0447 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 13.7% (pctl 96)

Patch early

A public exploit exists.

Description

The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS13.69% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2003-07-24
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD