Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2005-2117 | First vendor Publication | 2005-10-21 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:H/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 5.1 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | High |
Cvss Expoit Score | 4.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2117 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:1291 | |||
Oval ID: | oval:org.mitre.oval:def:1291 | ||
Title: | Windows Explorer Web View Script Injection Vulnerability | ||
Description: | Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-2117 | Version: | 6 |
Platform(s): | Microsoft Windows 2000 | Product(s): | |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Os | 1 | |
Os | 1 | |
Os | 2 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
19898 | Microsoft Windows Web View Arbitrary Script Injection |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows malformed shortcut file with comment buffer overflow attempt RuleID : 4644 - Revision : 18 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows malformed shortcut file buffer overflow attempt RuleID : 4643 - Revision : 21 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows malformed shortcut file with comment buffer overflow attempt RuleID : 27719 - Revision : 3 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows malformed shortcut file buffer overflow attempt RuleID : 27718 - Revision : 3 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows download of .lnk file that executes cmd.exe detected RuleID : 17442 - Revision : 13 - Type : FILE-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2005-10-11 | Name : Vulnerabilities in the Windows Shell could allow an attacker to execute arbit... File : smb_nt_ms05-049.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:21:48 |
|
2024-11-28 12:07:13 |
|
2021-05-04 12:03:02 |
|
2021-04-22 01:03:19 |
|
2020-05-23 00:16:40 |
|
2018-10-13 00:22:31 |
|
2017-10-11 09:23:32 |
|
2016-04-26 13:38:20 |
|
2014-02-17 10:31:59 |
|
2013-05-11 11:28:15 |
|