Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2004-1331 | First vendor Publication | 2004-11-16 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:H/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 2.6 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | High |
Cvss Expoit Score | 4.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1331 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 | |
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
11918 | Microsoft IE execCommand() File Extension Spoofing Microsoft Internet Explorer contains a flaw that may allow a remote attacker to bypass security settings. The issue is triggered when the 'Hide file extensions for known file types' option is enabled by default. It is possible for a remote attacker to create a malicious Web page that contains a specially crafted HTTP 404 error message, which would invoke the 'execCommand' function to bypass the "File Download - Security Warning" dialog and save arbitrary files on the system resulting in a loss of integrity. |
11917 | Microsoft Windows XP SP2 Spoofed Content-Location Warning Bypass Microsoft Windows contains a flaw that may allow a remote attacker to bypass security settings. By creating a specially crafted 'Content-Location' HTTP header, a remote attacker could bypass the 'File Download - Security Warning' dialog and save arbitrary files on the system resulting in a loss of integrity. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Internet Explorer file type spoofing attempt RuleID : 27063 - Revision : 2 - Type : BROWSER-IE |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:53 |
|
2024-11-28 12:06:19 |
|
2021-07-27 00:24:37 |
|
2021-07-24 01:44:14 |
|
2021-07-24 01:01:45 |
|
2021-07-23 17:24:41 |
|
2021-05-04 12:02:29 |
|
2021-04-22 01:02:40 |
|
2020-05-23 00:15:59 |
|
2017-07-11 12:01:35 |
|
2016-04-26 12:58:07 |
|
2014-01-19 21:22:23 |
|
2013-05-11 11:44:45 |
|