← Vulnerability feed

Vulnerability record · CVE-2003-0816 · published 3 February 2004

CVE-2003-0816: Internet Explorer zone restriction bypass via script URLs

Microsoft · Ie

Internet Explorer 6 SP1 and earlier fails to enforce zone restrictions when handling file: URLs containing JavaScript, allowing script to run in the context of another domain. Multiple vectors are documented, including NavigateAndFind, window.open, base tag href manipulation, Iframe loading of the search window, and caching javascript: URLs in history. This undermines the browser's cross-domain and zone trust model, which is the core defense separating untrusted web content from local or privileged zones.

7.5 CVSS 2.0 High EPSS 48% · top 1.2%
7.5CVSS 2.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
60References
16 Jun 2026Last modified by NVD

Description

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityThe flaw is a serious cross-domain bypass with a high EPSS score, but it affects a long-obsolete browser and the record shows no KEV listing or confirmed in-the-wild exploitation.

What it is

Internet Explorer 6 SP1 and earlier fails to enforce zone restrictions when handling file: URLs containing JavaScript, allowing script to run in the context of another domain. Multiple vectors are documented, including NavigateAndFind, window.open, base tag href manipulation, Iframe loading of the search window, and caching javascript: URLs in history. This undermines the browser's cross-domain and zone trust model, which is the core defense separating untrusted web content from local or privileged zones.

Impact

An attacker can execute script in a victim's browser under a domain or zone they should not control, enabling theft of cookies or data and other actions permitted to the impersonated origin. The CVSS 2.0 vector (C:P/I:P/A:P) indicates partial confidentiality, integrity and availability impact.

Attack surface

Reached remotely over the network with no authentication required (AV:N/AC:L/Au:N); the victim must load attacker-controlled content or follow a crafted link, so some user interaction is implied by the browser-based vectors. No affected version list beyond IE 6 SP1 and earlier is given in the record.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is high (0.48374, 98.8th percentile) and the references are public Bugtraq and SafeCenter proof-of-concept pages, indicating public technical detail exists. The record does not confirm active exploitation in the wild.

What to do

  • Apply Microsoft security bulletin MS03-048, the vendor patch referenced in the record, or upgrade to a supported Internet Explorer version.
  • Disable or restrict ActiveX and script execution for untrusted zones, and raise Internet zone restrictions.
  • Block or filter file: URLs and javascript: URLs delivered from web content at the proxy or browser policy level.
  • Retire IE 6 SP1 and earlier from any environment still running it, since the product is long out of support.
  • Educate users not to follow unsolicited links or open untrusted pages in legacy IE.

Detection

  • Monitor proxy and web logs for requests containing file: or javascript: URL patterns in query strings or referrers.
  • Alert on browser processes loading local file: URLs immediately after web navigation.
  • Review endpoint telemetry for IE 6 or earlier versions still present in the estate.
  • Hunt for known proof-of-concept page names from the SafeCenter references in web or DNS logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=106321638416884&w=2
http://marc.info/?l=bugtraq&m=106321693517858&w=2
http://marc.info/?l=bugtraq&m=106321781819727&w=2
http://marc.info/?l=bugtraq&m=106321882821788&w=2
http://marc.info/?l=bugtraq&m=106322063729496&w=2
http://marc.info/?l=bugtraq&m=106322240132721&w=2
http://secunia.com/advisories/10192
http://securitytracker.com/id?1007687
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html
http://www.kb.cert.org/vuls/id/652452 PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/771604 US Government Resource
http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm
http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM
http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm
http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM
http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM
http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM
http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM
http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM
http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM
http://www.securityfocus.com/archive/1/336937
http://www.securityfocus.com/archive/1/337086
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A361
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A362
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A363
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A409
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A416
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A459
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A479
http://marc.info/?l=bugtraq&m=106321638416884&w=2
http://marc.info/?l=bugtraq&m=106321693517858&w=2
http://marc.info/?l=bugtraq&m=106321781819727&w=2
http://marc.info/?l=bugtraq&m=106321882821788&w=2
http://marc.info/?l=bugtraq&m=106322063729496&w=2
http://marc.info/?l=bugtraq&m=106322240132721&w=2
http://secunia.com/advisories/10192
http://securitytracker.com/id?1007687
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html
http://www.kb.cert.org/vuls/id/652452 PatchThird Party AdvisoryUS Government Resource

Track CVE-2003-0816 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-0313Adobe Flash Player use-after-free allows remote code executionAdobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x…KEVEPSS 95%analysed9.8CVE-2015-0311Adobe Flash Player unspecified flaw allows remote code executionCVE-2015-0311 is an unspecified vulnerability in Adobe Flash Player affecting versions through 13.0.0.262, 14.x, 15.x, and 16.x through 16.0.0.287 on…KEVEPSS 86%analysed9.8CVE-2014-1776Internet Explorer use-after-free in CMarkup::IsConnectedToPrimaryMarkupMicrosoft Internet Explorer 6 through 11 contains a use-after-free in the CMarkup::IsConnectedToPrimaryMarkup function that allows remote code execut…KEVEPSS 83%analysed8.8CVE-2021-27085Microsoft Internet Explorer remote code execution flawCVE-2021-27085 is a remote code execution vulnerability in Microsoft Internet Explorer. The record gives only a one-line description and no root-caus…KEVEPSS 5.4%analysed8.8CVE-2021-26411Microsoft Internet Explorer and Edge use-after-free memory corruptionCVE-2021-26411 is a use-after-free (CWE-416) memory corruption flaw in Microsoft Internet Explorer, with Microsoft Edge also listed as an affected pr…KEVEPSS 81%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2017-0222Internet Explorer memory corruption out-of-bounds write RCEInternet Explorer improperly accesses objects in memory, causing an out-of-bounds write (CWE-787) that can be turned into remote code execution. The …KEVEPSS 30%analysed8.8CVE-2017-0210Internet Explorer cross-domain policy bypass elevation of privilegeInternet Explorer fails to properly enforce cross-domain policies, allowing an attacker to read information from one domain and inject it into anothe…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2003-0816), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.