Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2004-08-17 21:00
Updated : 2021-07-23 05:55
NVD link : CVE-2004-0839
Mitre link : CVE-2004-0839
JSON object : View
CWE
Products Affected
microsoft
- windows_2003_server
- windows_me
- windows_98se
- windows_98
- windows_xp
- internet_explorer
- ie
- windows_2000
nortel
- symposium_web_centre_portal
- optivity_telephony_manager
- mobile_voice_client_2050
- symposium_web_client
- ip_softphone_2050
avaya
- s8100
- ip600_media_servers
- definity_one_media_server
- s3400
- modular_messaging_message_storage_server