Vulnerability record · CVE-2002-0648 · published 24 September 2002
CVE-2002-0648: Internet Explorer XML data-island script flaw exposes local files
Microsoft · Internet Explorer
The legacy <script> data-island capability for XML in Internet Explorer 5.01, 5.5, and 6.0 lets a remote attacker read arbitrary XML files and portions of other local files by pointing a URL's "src" attribute at a local file. This is a cross-domain information disclosure issue in a browser feature that was widely deployed at the time. It matters because a malicious web page could silently pull local file content into attacker-readable output.
Description
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityConfidentiality-only impact with no confirmed exploitation, but the affected browser versions are obsolete and the EPSS score is high.
What it is
The legacy <script> data-island capability for XML in Internet Explorer 5.01, 5.5, and 6.0 lets a remote attacker read arbitrary XML files and portions of other local files by pointing a URL's "src" attribute at a local file. This is a cross-domain information disclosure issue in a browser feature that was widely deployed at the time. It matters because a malicious web page could silently pull local file content into attacker-readable output.
Impact
An attacker gains read access to arbitrary XML files and portions of other local files on the victim's machine. The exposure is limited to confidentiality; there is no integrity or availability impact per the CVSS vector.
Attack surface
Reached over the network via a crafted web page or URL that a victim loads in Internet Explorer; no authentication is required. The CVSS vector (AV:N/AC:L/Au:N) indicates no user interaction beyond visiting the page, though the description implies the victim must load the malicious content.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is high (0.48441, 98.8th percentile), suggesting elevated predicted likelihood, but that is a model estimate, not evidence of active exploitation.
What to do
- Apply Microsoft security bulletin MS02-047, which addresses this issue, or upgrade to a supported Internet Explorer version.
- Disable or restrict the legacy XML data-island <script> capability where policy allows.
- Enforce browser security zones that block local file access from remote content.
- Retire IE 5.01, 5.5, and 6.0 from production use; these versions are long out of support.
Detection
- Monitor for IE processes reading local XML or file paths shortly after browsing activity.
- Review proxy and web logs for pages containing XML data-island script constructs with src attributes pointing to local paths.
- Use the OVAL definitions referenced in the record to scan for vulnerable IE versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0648 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0648), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.