CVE-2004-0839

4 documents4 sources
Severity
5.0MEDIUM
EPSS
42.0%
top 2.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateApr 29

Description

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m47g-cqxq-6vwr: Internet Explorer in Windows XP SP2, and other versions including 52022-04-29
CVEList
CVE-2004-0839: Internet Explorer in Windows XP SP2, and other versions including 52004-09-14
VulnCheck
Microsoft Internet Explorer Arbitrary Program Installation Vulnerability2004
CVE-2004-0839 (MEDIUM CVSS 5) | Internet Explorer in Windows XP SP2 | cvebase.io