CVE-2003-0446 | Microsoft Internet Explorer 5.5/6.0 Error Message cross site scripting (EDB-22783 / Nessus ID 11492)
A vulnerability was found in Microsoft Internet Explorer 5.5/6.0. It has been rated as critical. This issue affects some unknown processing of the component Error Message Handler. The manipulation with the input http://[host.with.unparsable.xml.file]/flaw.xml?<script>alert(document.cookie)</script> leads to basic cross site scripting.
The identification of this vulnerability is CVE-2003-0446. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.