Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/GuiMatosInfra/explorer2sectool
- https://github.com/xaitax/SploitScan