← All CVEs

CVE-2003-0814

high · 7.5

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.

7.5
CVSS
27.7%
EPSS (exploit prob.)
98th
EPSS percentile
2004-02-03
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
microsoftie6.0
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.5
microsoftinternet_explorer5.5
microsoftinternet_explorer5.5
microsoftinternet_explorer6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2003-0814