CVE-2012-6502
low · 2.6Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a name-value pair from a local file via a \\127.0.0.1\C$\ sequence.
2.6
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2013-01-22
Published
AV:N/AC:H/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_explorer | 6 |
| microsoft | internet_explorer | 6 |
| microsoft | internet_explorer | 7 |
| microsoft | internet_explorer | 7.0.5730 |
| microsoft | internet_explorer | 8 |
| microsoft | internet_explorer | 9 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-6502