CVE-2003-1027
published 2004-01-20CVE-2003-1027: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
38.05%
98.4th percentile
Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-32xq-3j3p-872g: Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by callin
ghsa_unreviewed·2022-04-29·CVSS 10.0
CVE-2003-0823 [CRITICAL] GHSA-32xq-3j3p-872g: Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by callin
Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.
GHSA
GHSA-j6fj-77f5-j227: Internet Explorer 5
ghsa_unreviewed·2022-04-29·CVSS 7.5
CVE-2003-1027 [HIGH] GHSA-j6fj-77f5-j227: Internet Explorer 5
Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=106979479719446&w=2http://marc.info/?l=bugtraq&m=107038202225587&w=2http://www.kb.cert.org/vuls/id/413886http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2http://www.securitytracker.com/id?1006036http://www.us-cert.gov/cas/techalerts/TA04-033A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004https://exchange.xforce.ibmcloud.com/vulnerabilities/13844https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A527https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A529https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A530https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A531https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A532https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A534https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A629http://marc.info/?l=bugtraq&m=106979479719446&w=2http://marc.info/?l=bugtraq&m=107038202225587&w=2http://www.kb.cert.org/vuls/id/413886http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2http://www.securitytracker.com/id?1006036http://www.us-cert.gov/cas/techalerts/TA04-033A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004https://exchange.xforce.ibmcloud.com/vulnerabilities/13844https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A527https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A529https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A530https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A531https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A532https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A534https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A629
2004-01-20
Published