peter bassill · operator
$ cve CVE-2003-1026 JSON

CVE-2003-1026 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 39.2% (pctl 99)

Patch early

A public exploit exists.

Description

Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS39.21% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2004-01-20
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftie
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD