CVE-2003-0447 EXPLOIT
5.1
MEDIUM · CVSS 2.0 · EPSS 13.7% (pctl 96)
Patch early
A public exploit exists.
Description
The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.
Scoring
| CVSS | 5.1 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
| EPSS | 13.69% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-07-24 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 5 - Custom HTTP Error HTML Injection | 2003-06-17 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005763.html
- http://marc.info/?l=bugtraq&m=105585933614773&w=2
- http://marc.info/?l=ntbugtraq&m=105585142406147&w=2
- http://security.greymagic.com/adv/gm014-ie/
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005763.html
- http://marc.info/?l=bugtraq&m=105585933614773&w=2
- http://marc.info/?l=ntbugtraq&m=105585142406147&w=2
- http://security.greymagic.com/adv/gm014-ie/
→ the Explorer · watch your stack · NVD