{"api_version":"1","generated_at":"2026-07-23T07:30:01+00:00","cve":"CVE-2003-0815","urls":{"html":"https://cve.report/CVE-2003-0815","api":"https://cve.report/api/cve/CVE-2003-0815.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0815","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0815"},"summary":{"title":"CVE-2003-0815","description":"Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the \"Function Pointer Override Cross Domain\" vulnerability.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-02-03 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/9014","name":"http://www.securityfocus.com/bid/9014","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Microsoft Internet Explorer Function Pointer Override Cross-Domain Access Violation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS03-048 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/7889","name":"http://www.osvdb.org/7889","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=106322542104656&w=2","name":"http://marc.info/?l=bugtraq&m=106322542104656&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'MSIE->Findeath: break caller-based authorization' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/10192","name":"http://secunia.com/advisories/10192","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Microsoft Internet Explorer Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html","name":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus Bugtraq: MSIE->LinkillerSaveRef:another caller-based authorization","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=106321757619047&w=2","name":"http://marc.info/?l=bugtraq&m=106321757619047&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'MSIE->LinkillerJPU:another caller-based authorization(is broken).' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1007687","name":"http://securitytracker.com/id?1007687","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer Various Cross-Domain Flaws Permit Remote Scripting in Arbitrary Domains - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ciac.org/ciac/bulletins/o-021.shtml","name":"http://www.ciac.org/ciac/bulletins/o-021.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/337086","name":"http://www.securityfocus.com/archive/1/337086","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM","name":"http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"safecenter.net is for sale","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/7888","name":"http://www.osvdb.org/7888","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13676","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13676","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM","name":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"safecenter.net is for sale","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM","name":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"safecenter.net is for sale","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0815","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0815","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"815","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"815","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"815","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"815","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"815","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"815","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"815","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.5","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"815","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.5","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"815","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:05:12.551Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"O-021","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/o-021.shtml"},{"name":"20030910 MSIE->LinkillerJPU:another caller-based authorization(is broken).","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=106321757619047&w=2"},{"name":"20030910 MSIE->LinkillerSaveRef:another caller-based authorization","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html"},{"name":"oval:org.mitre.oval:def:351","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351"},{"name":"ie-pointer-zone-bypass(13676)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13676"},{"name":"oval:org.mitre.oval:def:472","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472"},{"name":"7889","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/7889"},{"name":"MS03-048","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048"},{"name":"1007687","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1007687"},{"name":"20030911 LiuDieYu's missing files are here.","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/337086"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM"},{"name":"oval:org.mitre.oval:def:353","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353"},{"name":"oval:org.mitre.oval:def:359","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359"},{"name":"20030910 MSIE->Findeath: break caller-based authorization","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=106322542104656&w=2"},{"name":"oval:org.mitre.oval:def:356","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356"},{"name":"9014","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9014"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM"},{"name":"oval:org.mitre.oval:def:357","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357"},{"name":"oval:org.mitre.oval:def:352","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352"},{"name":"7888","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/7888"},{"name":"10192","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/10192"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-09-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the \"Function Pointer Override Cross Domain\" vulnerability."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"O-021","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/o-021.shtml"},{"name":"20030910 MSIE->LinkillerJPU:another caller-based authorization(is broken).","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=106321757619047&w=2"},{"name":"20030910 MSIE->LinkillerSaveRef:another caller-based authorization","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html"},{"name":"oval:org.mitre.oval:def:351","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351"},{"name":"ie-pointer-zone-bypass(13676)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13676"},{"name":"oval:org.mitre.oval:def:472","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472"},{"name":"7889","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/7889"},{"name":"MS03-048","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048"},{"name":"1007687","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1007687"},{"name":"20030911 LiuDieYu's missing files are here.","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/337086"},{"tags":["x_refsource_MISC"],"url":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM"},{"name":"oval:org.mitre.oval:def:353","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353"},{"name":"oval:org.mitre.oval:def:359","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359"},{"name":"20030910 MSIE->Findeath: break caller-based authorization","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=106322542104656&w=2"},{"name":"oval:org.mitre.oval:def:356","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356"},{"name":"9014","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9014"},{"tags":["x_refsource_MISC"],"url":"http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM"},{"tags":["x_refsource_MISC"],"url":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM"},{"name":"oval:org.mitre.oval:def:357","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357"},{"name":"oval:org.mitre.oval:def:352","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352"},{"name":"7888","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/7888"},{"name":"10192","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/10192"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0815","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the \"Function Pointer Override Cross Domain\" vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"O-021","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/o-021.shtml"},{"name":"20030910 MSIE->LinkillerJPU:another caller-based authorization(is broken).","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=106321757619047&w=2"},{"name":"20030910 MSIE->LinkillerSaveRef:another caller-based authorization","refsource":"BUGTRAQ","url":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html"},{"name":"oval:org.mitre.oval:def:351","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351"},{"name":"ie-pointer-zone-bypass(13676)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13676"},{"name":"oval:org.mitre.oval:def:472","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472"},{"name":"7889","refsource":"OSVDB","url":"http://www.osvdb.org/7889"},{"name":"MS03-048","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048"},{"name":"1007687","refsource":"SECTRACK","url":"http://securitytracker.com/id?1007687"},{"name":"20030911 LiuDieYu's missing files are here.","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/337086"},{"name":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM","refsource":"MISC","url":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM"},{"name":"oval:org.mitre.oval:def:353","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353"},{"name":"oval:org.mitre.oval:def:359","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359"},{"name":"20030910 MSIE->Findeath: break caller-based authorization","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=106322542104656&w=2"},{"name":"oval:org.mitre.oval:def:356","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356"},{"name":"9014","refsource":"BID","url":"http://www.securityfocus.com/bid/9014"},{"name":"http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM","refsource":"MISC","url":"http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM"},{"name":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM","refsource":"MISC","url":"http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM"},{"name":"oval:org.mitre.oval:def:357","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357"},{"name":"oval:org.mitre.oval:def:352","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352"},{"name":"7888","refsource":"OSVDB","url":"http://www.osvdb.org/7888"},{"name":"10192","refsource":"SECUNIA","url":"http://secunia.com/advisories/10192"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0815","datePublished":"2004-01-14T05:00:00.000Z","dateReserved":"2003-09-18T00:00:00.000Z","dateUpdated":"2024-08-08T02:05:12.551Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-02-03 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*","matchCriteriaId":"24DF2AB3-DEAB-4D70-986E-FFBB7E64B96A"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"3A04FEA6-37B0-44B0-844F-55652ABA1F85"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*","matchCriteriaId":"4D56FB8E-2553-47C1-82A2-9E59023780CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*","matchCriteriaId":"8541EEED-94F4-42F8-9719-57F3EC85D52B"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*","matchCriteriaId":"40372520-08CF-4F64-A7AC-7E0AE0964138"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*","matchCriteriaId":"40F8042F-C621-45AE-9F8C-70469579643A"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*","matchCriteriaId":"2CD04E07-3664-4D4F-BF3E-6B33AF0F2D12"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*","matchCriteriaId":"D05ED9D0-CF78-4FAD-9371-6FB3D5825148"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*","matchCriteriaId":"A19F6133-25D1-44A5-B6B9-354703436783"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"815","Ordinal":"1","Title":"CVE-2003-0815","CVE":"CVE-2003-0815","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"815","Ordinal":"1","NoteData":"Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the \"Function Pointer Override Cross Domain\" vulnerability.","Type":"Description","Title":"CVE-2003-0815"},{"CveYear":"2003","CveId":"815","Ordinal":"2","NoteData":"2004-01-14","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"815","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}