Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2004-08-18 04:00
Updated : 2021-07-23 12:55
NVD link : CVE-2004-0839
Mitre link : CVE-2004-0839
CVE.ORG link : CVE-2004-0839
JSON object : View
Products Affected
microsoft
- windows_me
- windows_xp
- ie
- windows_98se
- windows_2000
- internet_explorer
- windows_2003_server
- windows_98
nortel
- symposium_web_client
- mobile_voice_client_2050
- symposium_web_centre_portal
- optivity_telephony_manager
- ip_softphone_2050
avaya
- s8100
- modular_messaging_message_storage_server
- ip600_media_servers
- s3400
- definity_one_media_server
CWE