Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
20 Nov 2024, 23:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=109303291513335&w=2 - | |
References | () http://marc.info/?l=bugtraq&m=109336221826652&w=2 - | |
References | () http://seclists.org/lists/fulldisclosure/2004/Aug/0868.html - Vendor Advisory | |
References | () http://www.kb.cert.org/vuls/id/526089 - Patch, Third Party Advisory, US Government Resource | |
References | () http://www.securityfocus.com/bid/10973 - Exploit, Patch, Vendor Advisory | |
References | () http://www.us-cert.gov/cas/techalerts/TA04-293A.html - Patch, Third Party Advisory, US Government Resource | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/17044 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1563 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2073 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3773 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4152 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6272 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7721 - |
23 Jul 2021, 12:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:microsoft:ie:5.0.1:*:*:*:*:*:*:* cpe:2.3:a:microsoft:ie:5.0.1:sp3:*:*:*:*:*:* cpe:2.3:a:microsoft:ie:5.0.1:sp4:*:*:*:*:*:* cpe:2.3:a:microsoft:ie:5.5:*:*:*:*:*:*:* cpe:2.3:a:microsoft:ie:6.0:*:*:*:*:*:*:* cpe:2.3:a:microsoft:ie:5.0.1:sp1:*:*:*:*:*:* cpe:2.3:a:microsoft:ie:5.0.1:sp2:*:*:*:*:*:* cpe:2.3:a:microsoft:ie:5.5:sp2:*:*:*:*:*:* |
cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:* |
Information
Published : 2004-08-18 04:00
Updated : 2024-11-20 23:49
NVD link : CVE-2004-0839
Mitre link : CVE-2004-0839
CVE.ORG link : CVE-2004-0839
JSON object : View
Products Affected
avaya
- ip600_media_servers
- s3400
- definity_one_media_server
- s8100
- modular_messaging_message_storage_server
microsoft
- windows_98se
- windows_2003_server
- windows_me
- windows_xp
- internet_explorer
- ie
- windows_2000
- windows_98
nortel
- ip_softphone_2050
- mobile_voice_client_2050
- symposium_web_centre_portal
- optivity_telephony_manager
- symposium_web_client
CWE