Executive Summary

Informations
Name CVE-2003-1026 First vendor Publication 2004-01-20
Vendor Cve Last vendor Modification 2021-07-23

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026

CAPEC : Common Attack Pattern Enumeration & Classification

Id Name
CAPEC-17 Accessing, Modifying or Executing Executable Files
CAPEC-30 Hijacking a Privileged Thread of Execution
CAPEC-35 Leverage Executable Code in Nonexecutable Files

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:630
 
Oval ID: oval:org.mitre.oval:def:630
Title: IE v5.01,SP2 Travel Log Cross Domain Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1026
Version: 5
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:643
 
Oval ID: oval:org.mitre.oval:def:643
Title: IE v5.01,SP3 Travel Log Cross Domain Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1026
Version: 5
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:687
 
Oval ID: oval:org.mitre.oval:def:687
Title: IE v5.01,SP4 Travel Log Cross Domain Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1026
Version: 5
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:689
 
Oval ID: oval:org.mitre.oval:def:689
Title: IE v5.5,SP2 Travel Log Cross Domain Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1026
Version: 3
Platform(s): Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:745
 
Oval ID: oval:org.mitre.oval:def:745
Title: IE v6.0 (XP) Travel Log Cross Domain Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1026
Version: 4
Platform(s): Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:774
 
Oval ID: oval:org.mitre.oval:def:774
Title: IE v6.0,SP1 Travel Log Cross Domain Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1026
Version: 5
Platform(s): Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:805
 
Oval ID: oval:org.mitre.oval:def:805
Title: IE v6.0,SP1 (Server 2003) Travel Log Cross Domain Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1026
Version: 6
Platform(s): Microsoft Windows Server 2003
Product(s): Microsoft Internet Explorer
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Application 9

ExploitDB Exploits

id Description
2004-02-03 Microsoft Internet Explorer 5 NavigateAndFind() Cross-Zone Policy Vulnerability
2004-02-04 MS Internet Explorer URL Injection in History List (MS04-004)

OpenVAS Exploits

Date Description
2005-11-03 Name : IE 5.01 5.5 6.0 Cumulative patch (890923)
File : nvt/smb_nt_ms02-005.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
3791 Microsoft IE Travel Log Arbitrary Script Execution

Microsoft Internet Explorer contains a flaw that allows a remote cross zone scripting attack. This flaw exists because the application might execute code in the Local Machine zone if the page contains a subframe. This could allow a user to create a specially crafted URL that when viewed would execute arbitrary code in a user's browser within the security context of the currently logged on user, leading to a loss of confidentiality, integrity and availability.

Snort® IPS/IDS

Date Description
2014-11-16 Microsoft Internet Explorer URL domain spoof attempt
RuleID : 31888 - Revision : 2 - Type : BROWSER-IE
2014-11-16 Microsoft Internet Explorer URL domain spoof attempt
RuleID : 31887 - Revision : 2 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer URL canonicalization address bar spoofing attempt
RuleID : 15933 - Revision : 8 - Type : BROWSER-IE

Sources (Detail)

Source Url
BUGTRAQ http://marc.info/?l=bugtraq&m=106979349517578&w=2
http://marc.info/?l=bugtraq&m=107038202225587&w=2
CERT http://www.us-cert.gov/cas/techalerts/TA04-033A.html
CERT-VN http://www.kb.cert.org/vuls/id/784102
MISC http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu
MS https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04...
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/13846

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
Date Informations
2021-07-27 00:24:37
  • Multiple Updates
2021-07-24 01:44:15
  • Multiple Updates
2021-07-24 01:01:36
  • Multiple Updates
2021-07-23 17:24:41
  • Multiple Updates
2021-07-23 01:44:03
  • Multiple Updates
2021-07-23 01:01:35
  • Multiple Updates
2021-07-22 21:24:59
  • Multiple Updates
2021-05-04 12:02:10
  • Multiple Updates
2021-04-22 01:02:18
  • Multiple Updates
2020-05-23 00:15:33
  • Multiple Updates
2018-10-13 00:22:28
  • Multiple Updates
2017-10-11 09:23:19
  • Multiple Updates
2017-07-11 12:01:19
  • Multiple Updates
2016-10-18 12:01:15
  • Multiple Updates
2016-04-26 12:39:28
  • Multiple Updates
2013-05-11 11:53:29
  • Multiple Updates