Executive Summary

Informations
Name CVE-2003-1027 First vendor Publication 2004-01-20
Vendor Cve Last vendor Modification 2021-07-23

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:527
 
Oval ID: oval:org.mitre.oval:def:527
Title: IE v5.01,SP2 Function Pointer Drag and Drop Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1027
Version: 5
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:529
 
Oval ID: oval:org.mitre.oval:def:529
Title: IE v5.01,SP3 Function Pointer Drag and Drop Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1027
Version: 5
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:530
 
Oval ID: oval:org.mitre.oval:def:530
Title: IE v5.01,SP4 Function Pointer Drag and Drop Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1027
Version: 5
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:531
 
Oval ID: oval:org.mitre.oval:def:531
Title: IE v5.5,SP2 Function Pointer Drag and Drop Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1027
Version: 3
Platform(s): Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:532
 
Oval ID: oval:org.mitre.oval:def:532
Title: IE v6.0 Function Pointer Drag and Drop Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1027
Version: 4
Platform(s): Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:534
 
Oval ID: oval:org.mitre.oval:def:534
Title: IE v6.0,SP1 Function Pointer Drag and Drop Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1027
Version: 5
Platform(s): Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:629
 
Oval ID: oval:org.mitre.oval:def:629
Title: IE v6.0,SP1 (Server 2003) Function Pointer Drag and Drop Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1027
Version: 6
Platform(s): Microsoft Windows Server 2003
Product(s): Microsoft Internet Explorer
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Application 9

ExploitDB Exploits

id Description
2004-02-03 Microsoft Internet Explorer 5 NavigateAndFind() Cross-Zone Policy Vulnerability
2004-02-04 MS Internet Explorer URL Injection in History List (MS04-004)

OpenVAS Exploits

Date Description
2005-11-03 Name : IE 5.01 5.5 6.0 Cumulative patch (890923)
File : nvt/smb_nt_ms02-005.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
7891 Microsoft Windows IE window.moveBy Function Pointer Hijack (HijackClickV2)

Windows contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the OS allowing mouse events to control certain window operations via method caching. This may allow an attacker to include a file from a remote host that could be executed via another vulnerability.

Snort® IPS/IDS

Date Description
2014-11-16 Microsoft Internet Explorer URL domain spoof attempt
RuleID : 31888 - Revision : 2 - Type : BROWSER-IE
2014-11-16 Microsoft Internet Explorer URL domain spoof attempt
RuleID : 31887 - Revision : 2 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer URL canonicalization address bar spoofing attempt
RuleID : 15933 - Revision : 8 - Type : BROWSER-IE

Sources (Detail)

Source Url
BUGTRAQ http://marc.info/?l=bugtraq&m=106979479719446&w=2
http://marc.info/?l=bugtraq&m=107038202225587&w=2
CERT http://www.us-cert.gov/cas/techalerts/TA04-033A.html
CERT-VN http://www.kb.cert.org/vuls/id/413886
MISC http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2
MS https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04...
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
SECTRACK http://www.securitytracker.com/id?1006036
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/13844

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
Date Informations
2021-07-27 00:24:37
  • Multiple Updates
2021-07-24 01:44:15
  • Multiple Updates
2021-07-24 01:01:36
  • Multiple Updates
2021-07-23 17:24:41
  • Multiple Updates
2021-07-23 01:44:03
  • Multiple Updates
2021-07-23 01:01:35
  • Multiple Updates
2021-07-22 21:24:59
  • Multiple Updates
2021-05-04 12:02:10
  • Multiple Updates
2021-04-22 01:02:18
  • Multiple Updates
2020-05-23 00:15:33
  • Multiple Updates
2018-10-13 00:22:28
  • Multiple Updates
2017-10-11 09:23:19
  • Multiple Updates
2017-07-11 12:01:19
  • Multiple Updates
2016-10-18 12:01:15
  • Multiple Updates
2016-04-26 12:39:28
  • Multiple Updates
2013-05-11 11:53:29
  • Multiple Updates