CVE-2003-0309

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/06/2003
Last modified:
03/04/2025

Description

Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:internet_explorer:6.0.2800:*:*:*:*:*:*:*