CVE-2003-1026
published 2004-01-20CVE-2003-1026: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the…
PriorityP336critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
39.21%
98.4th percentile
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect javascript: protocol URLs being injected into the browser history list via location assignment, particularly those referencing history.length or history.back()/back navigation triggers. ↗
- →Monitor for ActiveXObject instantiation of ADODB.Stream from within Internet Explorer browser context, which is used by the payload to write arbitrary files to disk. ↗
- →Detect cross-zone javascript: protocol URL execution triggered by history.back() navigation in sub-frames, which causes the script to execute in the top window's (Local Machine) zone. ↗
- →Alert on file creation events on the user Desktop originating from iexplore.exe or browser child processes, especially .txt files written via ADODB.Stream SaveToFile. ↗
- ·The exploit targets Internet Explorer versions 5.01 through 6 SP1 specifically; patched by Microsoft security bulletin MS04-004. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=106979349517578&w=2http://marc.info/?l=bugtraq&m=107038202225587&w=2http://www.kb.cert.org/vuls/id/784102http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpuhttp://www.us-cert.gov/cas/techalerts/TA04-033A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004https://exchange.xforce.ibmcloud.com/vulnerabilities/13846https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A630https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A643https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A687https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A689https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A745https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A774https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A805http://marc.info/?l=bugtraq&m=106979349517578&w=2http://marc.info/?l=bugtraq&m=107038202225587&w=2http://www.kb.cert.org/vuls/id/784102http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpuhttp://www.us-cert.gov/cas/techalerts/TA04-033A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004https://exchange.xforce.ibmcloud.com/vulnerabilities/13846https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A630https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A643https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A687https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A689https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A745https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A774https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A805
2004-01-20
Published