Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.
Loading...
Loading...
Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.
February 16, 2001
April 16, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Microsoft Internet Explorer 5 - 'INPUT TYPE=FILE' Remote File Upload
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2001-0089
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.