CVE-2003-0823
published 2004-02-03CVE-2003-0823: Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
26.00%
97.8th percentile
Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| mozilla | firefox | < 2.0.0.17 | 2.0.0.17 |
| mozilla | firefox | >= 3.0 < 3.0.2 | 3.0.2 |
| mozilla | seamonkey | < 1.1.12 | 1.1.12 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mozilla: Forced mouse drag
vendor_redhat·2008-09-23·CVSS 7.5
CVE-2008-3837 [HIGH] mozilla: Forced mouse drag
mozilla: Forced mouse drag
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
GHSA
GHSA-w2pf-f3c3-85m7: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2008-3837 [HIGH] GHSA-w2pf-f3c3-85m7: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
GHSA
GHSA-32xq-3j3p-872g: Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by callin
ghsa_unreviewed·2022-04-29·CVSS 10.0
CVE-2003-0823 [CRITICAL] GHSA-32xq-3j3p-872g: Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by callin
Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.
GHSA
GHSA-j6fj-77f5-j227: Internet Explorer 5
ghsa_unreviewed·2022-04-29·CVSS 7.5
CVE-2003-1027 [HIGH] GHSA-j6fj-77f5-j227: Internet Explorer 5
Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=106322197932006&w=2http://secunia.com/advisories/10192http://www.kb.cert.org/vuls/id/413886http://www.securityfocus.com/archive/1/337086http://www.securitytracker.com/id?1006036https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A368https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A369https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A370https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A371https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A372https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A588https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A733http://marc.info/?l=bugtraq&m=106322197932006&w=2http://secunia.com/advisories/10192http://www.kb.cert.org/vuls/id/413886http://www.securityfocus.com/archive/1/337086http://www.securitytracker.com/id?1006036https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A368https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A369https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A370https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A371https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A372https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A588https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A733
2004-02-03
Published