Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2004-0839 | First vendor Publication | 2004-08-18 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html". |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:1563 | |||
Oval ID: | oval:org.mitre.oval:def:1563 | ||
Title: | IE v6.0,SP1 Drag-and-Drop Code Execution Vulnerability | ||
Description: | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html". | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2004-0839 | Version: | 5 |
Platform(s): | Microsoft Windows ME Microsoft Windows NT Microsoft Windows 2000 Microsoft Windows XP | Product(s): | Microsoft Internet Explorer |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:2073 | |||
Oval ID: | oval:org.mitre.oval:def:2073 | ||
Title: | IE v5.01,SP3 Drag-and-Drop Code Execution Vulnerability | ||
Description: | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html". | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2004-0839 | Version: | 4 |
Platform(s): | Microsoft Windows 2000 | Product(s): | Microsoft Internet Explorer |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:3773 | |||
Oval ID: | oval:org.mitre.oval:def:3773 | ||
Title: | IE v5.5,SP2 Drag-and-Drop Code Execution Vulnerability | ||
Description: | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html". | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2004-0839 | Version: | 4 |
Platform(s): | Microsoft Windows ME | Product(s): | Microsoft Internet Explorer |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:4152 | |||
Oval ID: | oval:org.mitre.oval:def:4152 | ||
Title: | IE v5.01,SP4 Drag-and-Drop Code Execution Vulnerability | ||
Description: | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html". | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2004-0839 | Version: | 4 |
Platform(s): | Microsoft Windows 2000 | Product(s): | Microsoft Internet Explorer |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:6272 | |||
Oval ID: | oval:org.mitre.oval:def:6272 | ||
Title: | IE v6.0,SP1 (Server 2003) Drag-and-Drop Code Execution Vulnerability | ||
Description: | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html". | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2004-0839 | Version: | 5 |
Platform(s): | Microsoft Windows Server 2003 | Product(s): | Microsoft Internet Explorer |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:7721 | |||
Oval ID: | oval:org.mitre.oval:def:7721 | ||
Title: | IE v6.0 Drag-and-Drop Code Execution Vulnerability | ||
Description: | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html". | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2004-0839 | Version: | 5 |
Platform(s): | Microsoft Windows XP | Product(s): | Microsoft Internet Explorer |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2004-10-20 | Microsoft Internet Explorer 5.x Valid File Drag and Drop Embedded Code Vulner... |
OpenVAS Exploits
Date | Description |
---|---|
2005-11-03 | Name : IE 5.01 5.5 6.0 Cumulative patch (890923) File : nvt/smb_nt_ms02-005.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
9070 | Microsoft IE dragDrop Arbitrary File Upload (What a Drag II) Microsoft IE contains a flaw that may allow an attacker to upload a malicious file. The issue is triggered when a user attempts a drag and drop action on a malicious html page. It is possible that the flaw may allow the saving of an arbitrary file in the startup folder which will be executed after the next reboot resulting in a loss of integrity. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | MSN Heartbeat ActiveX clsid access RuleID : 4167 - Revision : 16 - Type : BROWSER-PLUGINS |
2014-01-10 | Shell.Explorer ActiveX Object Access RuleID : 4166 - Revision : 10 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer mouse drag hijack RuleID : 21353 - Revision : 4 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer implicit drag and drop file installation attempt RuleID : 18299 - Revision : 8 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer Install Engine ActiveX clsid unicode access RuleID : 17589 - Revision : 4 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer Install Engine ActiveX clsid access RuleID : 17588 - Revision : 13 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Internet Explorer Shell.Explorer 2 ActiveX clsid access RuleID : 15122 - Revision : 15 - Type : BROWSER-PLUGINS |
2014-01-10 | Shell.Explorer 2 ActiveX function call unicode access RuleID : 15113 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer Shell.Explorer 2 ActiveX function call access RuleID : 15112 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Shell.Explorer 2 ActiveX clsid unicode access RuleID : 15111 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | MSN Heartbeat ActiveX clsid unicode access RuleID : 12956 - Revision : 7 - Type : WEB-ACTIVEX |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:59 |
|
2024-11-28 12:06:13 |
|
2021-07-27 00:24:37 |
|
2021-07-24 01:44:14 |
|
2021-07-24 01:01:44 |
|
2021-07-23 17:24:41 |
|
2021-07-23 01:44:03 |
|
2021-07-23 01:01:42 |
|
2021-07-22 21:24:58 |
|
2021-05-04 12:02:24 |
|
2021-04-22 01:02:33 |
|
2020-05-23 00:15:53 |
|
2019-04-30 21:19:18 |
|
2018-10-13 00:22:29 |
|
2017-10-11 09:23:23 |
|
2017-07-11 12:01:31 |
|
2016-10-18 12:01:23 |
|
2016-04-26 12:53:36 |
|
2014-01-19 21:22:18 |
|
2013-05-11 11:43:09 |
|