Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-050
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ246094
Source: Mitre, NVD
Published: 1999-12-08
Updated: 2025-04-03
Base Score: 5.1
Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P
Severity: Medium
Base Score: 6.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.03623