{"api_version":"1","generated_at":"2026-07-23T04:03:06+00:00","cve":"CVE-2002-1188","urls":{"html":"https://cve.report/CVE-2002-1188","api":"https://cve.report/api/cve/CVE-2002-1188.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1188","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1188"},"summary":{"title":"CVE-2002-1188","description":"Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka \"Temporary Internet Files folders Name Reading.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2002-12-11 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS02-066 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=103184415307193&w=2","name":"http://marc.info/?l=bugtraq&m=103184415307193&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'LEVERAGING CROSS-PROTOCOL SCRIPTING IN MSIE' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ciac.org/ciac/bulletins/n-018.shtml","name":"http://www.ciac.org/ciac/bulletins/n-018.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/10665.php","name":"http://www.iss.net/security_center/static/10665.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"ISS X-Force Database: ie-object-read-tif (10665): Microsoft Internet Explorer OBJECT tag could be used to read TIF folder name","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A444","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A444","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A690","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A690","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6217","name":"http://www.securityfocus.com/bid/6217","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer Object Tag Temporary Internet File Folder Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1188","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1188","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.5","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.5","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:19:27.498Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"MS02-066","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066"},{"name":"N-018","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/n-018.shtml"},{"name":"6217","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6217"},{"name":"ie-object-read-tif(10665)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10665.php"},{"name":"20020912 LEVERAGING CROSS-PROTOCOL SCRIPTING IN MSIE","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=103184415307193&w=2"},{"name":"oval:org.mitre.oval:def:690","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A690"},{"name":"oval:org.mitre.oval:def:444","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A444"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-11-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka \"Temporary Internet Files folders Name Reading.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-11-01T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"MS02-066","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066"},{"name":"N-018","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/n-018.shtml"},{"name":"6217","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6217"},{"name":"ie-object-read-tif(10665)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10665.php"},{"name":"20020912 LEVERAGING CROSS-PROTOCOL SCRIPTING IN MSIE","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=103184415307193&w=2"},{"name":"oval:org.mitre.oval:def:690","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A690"},{"name":"oval:org.mitre.oval:def:444","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A444"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1188","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka \"Temporary Internet Files folders Name Reading.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"MS02-066","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066"},{"name":"N-018","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/n-018.shtml"},{"name":"6217","refsource":"BID","url":"http://www.securityfocus.com/bid/6217"},{"name":"ie-object-read-tif(10665)","refsource":"XF","url":"http://www.iss.net/security_center/static/10665.php"},{"name":"20020912 LEVERAGING CROSS-PROTOCOL SCRIPTING IN MSIE","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=103184415307193&w=2"},{"name":"oval:org.mitre.oval:def:690","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A690"},{"name":"oval:org.mitre.oval:def:444","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A444"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1188","datePublished":"2004-09-01T04:00:00.000Z","dateReserved":"2002-10-04T00:00:00.000Z","dateUpdated":"2024-08-08T03:19:27.498Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-12-11 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"3A04FEA6-37B0-44B0-844F-55652ABA1F85"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*","matchCriteriaId":"4D56FB8E-2553-47C1-82A2-9E59023780CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*","matchCriteriaId":"8541EEED-94F4-42F8-9719-57F3EC85D52B"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*","matchCriteriaId":"40F8042F-C621-45AE-9F8C-70469579643A"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*","matchCriteriaId":"2CD04E07-3664-4D4F-BF3E-6B33AF0F2D12"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*","matchCriteriaId":"D05ED9D0-CF78-4FAD-9371-6FB3D5825148"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*","matchCriteriaId":"A19F6133-25D1-44A5-B6B9-354703436783"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1188","Ordinal":"1","Title":"CVE-2002-1188","CVE":"CVE-2002-1188","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1188","Ordinal":"1","NoteData":"Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka \"Temporary Internet Files folders Name Reading.\"","Type":"Description","Title":"CVE-2002-1188"},{"CveYear":"2002","CveId":"1188","Ordinal":"2","NoteData":"2004-09-01","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1188","Ordinal":"3","NoteData":"2006-10-31","Type":"Other","Title":"Modified"}]}}}