VULNERABILITY INTELLIGENCE

CVE-1999-0489

CVSS score10 HIGH
EPSS probability12.45%
CISA KEVNot currently listed
Published1999-05-17
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:C/I:C/A:C

Description

MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.

Primary references