CVE-2004-0839

Published Aug 18, 2004

Last updated 3 months ago

Overview

Description
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
Source
cve@mitre.org
NVD status
Modified
Products
ip600_media_servers, ie, internet_explorer, definity_one_media_server, s3400, s8100, ip_softphone_2050, mobile_voice_client_2050, optivity_telephony_manager, symposium_web_centre_portal, symposium_web_client, modular_messaging_message_storage_server, windows_2000, windows_2003_server, windows_98, windows_98se, windows_me, windows_xp

Risk scores

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:P/A:N

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.