CVE-2004-0839

Published Aug 18, 2004

Last updated 12 days ago

Overview

Description
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
Source
cve@mitre.org
NVD status
Modified
Products
ip600_media_servers, ie, internet_explorer, definity_one_media_server, s3400, s8100, ip_softphone_2050, mobile_voice_client_2050, optivity_telephony_manager, symposium_web_centre_portal, symposium_web_client, modular_messaging_message_storage_server, windows_2000, windows_2003_server, windows_98, windows_98se, windows_me, windows_xp

Risk scores

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:P/A:N

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.