CVE-2004-0475
published 2004-07-07CVE-2004-0475: The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\")…
PriorityP422medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
10.03%
95.1th percentile
The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\") before the target CHM file, as demonstrated using an "ms-its" URL to ntshared.chm. NOTE: this bug may overlap CVE-2003-1041.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q48v-h8j7-56w2: Internet Explorer 5
ghsa_unreviewed·2022-04-29·CVSS 5.1
CVE-2003-1041 [MEDIUM] GHSA-q48v-h8j7-56w2: Internet Explorer 5
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.
GHSA
GHSA-624v-gqcq-xp7r: The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local
ghsa_unreviewed·2022-04-29·CVSS 7.5
CVE-2004-0475 [HIGH] GHSA-624v-gqcq-xp7r: The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local
The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\") before the target CHM file, as demonstrated using an "ms-its" URL to ntshared.chm. NOTE: this bug may overlap CVE-2003-1041.
VulnCheck
Microsoft Internet Explorer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2003·CVSS 7.5
CVE-2003-1041 [HIGH] Microsoft Internet Explorer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Microsoft Internet Explorer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.
Affected: Microsoft Internet Explorer
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2004-07-07
Published