Name CVE-2004-0843 First vendor Publication 2004-11-03
Vendor Cve Last vendor Modification 2021-07-23

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:N)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:2487
Oval ID: oval:org.mitre.oval:def:2487
Title: IE v6.0 Plug-in Navigation Address Bar Spoofing Vulnerability
Description: Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2004-0843
Version: 5
Platform(s): Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:2537
Oval ID: oval:org.mitre.oval:def:2537
Title: IE v5.01,SP4 Plug-in Navigation Address Bar Spoofing Vulnerability
Description: Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2004-0843
Version: 4
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:3949
Oval ID: oval:org.mitre.oval:def:3949
Title: IE v5.01, SP3 Plug-in Navigation Address Bar Spoofing Vulnerability
Description: Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2004-0843
Version: 4
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:6313
Oval ID: oval:org.mitre.oval:def:6313
Title: IE v6.0,SP1 for Server 2003 Plug-in Navigation Address Bar Spoofing Vulnerability
Description: Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2004-0843
Version: 5
Platform(s): Microsoft Windows Server 2003
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:7095
Oval ID: oval:org.mitre.oval:def:7095
Title: IE v5.5,SP2 Plug-in Navigation Address Bar Spoofing Vulnerability
Description: Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2004-0843
Version: 4
Platform(s): Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:7194
Oval ID: oval:org.mitre.oval:def:7194
Title: IE v6.0,SP1 Plug-in Navigation Address Bar Spoofing Vulnerability
Description: Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2004-0843
Version: 5
Platform(s): Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:

CPE : Common Platform Enumeration

Application 1
Application 1

ExploitDB Exploits

id Description
2004-10-20 Microsoft Internet Explorer 5.x Valid File Drag and Drop Embedded Code Vulner...

OpenVAS Exploits

Date Description
2005-11-03 Name : IE 5.01 5.5 6.0 Cumulative patch (890923)
File : nvt/smb_nt_ms02-005.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
10707 Microsoft IE Plug-in Navigation Address Bar Spoofing

Internet Explorer contains a flaw that may allow a malicious user to spoof an address in a user's address bar. The issue is triggered when the victim visits a specially crafted web page and the Plug-in Navigation does not properly handle the request. It is possible that the flaw may allow the attacker to spoof a trusted web site resulting in a loss of integrity.

Snort® IPS/IDS

Date Description
2014-01-10 MSN Heartbeat ActiveX clsid access
RuleID : 4167 - Revision : 16 - Type : BROWSER-PLUGINS
2014-01-10 Shell.Explorer ActiveX Object Access
RuleID : 4166 - Revision : 10 - Type : WEB-ACTIVEX
2014-01-10 Microsoft Internet Explorer mouse drag hijack
RuleID : 21353 - Revision : 4 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer Install Engine ActiveX clsid unicode access
RuleID : 17589 - Revision : 4 - Type : WEB-ACTIVEX
2014-01-10 Microsoft Internet Explorer Install Engine ActiveX clsid access
RuleID : 17588 - Revision : 13 - Type : BROWSER-PLUGINS
2014-01-10 Microsoft Internet Explorer Shell.Explorer 2 ActiveX clsid access
RuleID : 15122 - Revision : 15 - Type : BROWSER-PLUGINS
2014-01-10 Shell.Explorer 2 ActiveX function call unicode access
RuleID : 15113 - Revision : 6 - Type : WEB-ACTIVEX
2014-01-10 Microsoft Internet Explorer Shell.Explorer 2 ActiveX function call access
RuleID : 15112 - Revision : 12 - Type : BROWSER-PLUGINS
2014-01-10 Shell.Explorer 2 ActiveX clsid unicode access
RuleID : 15111 - Revision : 6 - Type : WEB-ACTIVEX
2014-01-10 MSN Heartbeat ActiveX clsid unicode access
RuleID : 12956 - Revision : 7 - Type : WEB-ACTIVEX

Sources (Detail)

Source Url
CERT http://www.us-cert.gov/cas/techalerts/TA04-293A.html
CERT-VN http://www.kb.cert.org/vuls/id/625616
MS https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04...
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/17651

Alert History

