CVE-2004-1331
published 2004-11-16CVE-2004-1331: The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save…
PriorityP424low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
19.47%
97.1th percentile
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | internet_explorer | <= 7 | — |
| microsoft | internet_explorer | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-47hh-2ggx-7r2j: Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Security Warning" dialog box and download arbitrary
ghsa_unreviewed·2022-05-01·CVSS 2.6
CVE-2007-5456 [LOW] CWE-94 GHSA-47hh-2ggx-7r2j: Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Security Warning" dialog box and download arbitrary
Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Security Warning" dialog box and download arbitrary .exe files by placing a '?' (question mark) followed by a non-.exe filename after the .exe filename, as demonstrated by (1) .txt, (2) .cda, (3) .log, (4) .dif, (5) .sol, (6) .htt, (7) .itpc, (8) .itms, (9) .dvr-ms, (10) .dib, (11) .asf, (12) .tif, and unspecified other extensions, a different issue than CVE-2004-1331. NOTE: this issue might not cross privilege boundaries, although it does bypass an intended protection mechanism.
GHSA
GHSA-p882-x8vh-j9c7: The execCommand method in Microsoft Internet Explorer 6
ghsa_unreviewed·2022-04-29
CVE-2004-1331 [LOW] GHSA-p882-x8vh-j9c7: The execCommand method in Microsoft Internet Explorer 6
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2004-11/0260.htmlhttp://secunia.com/advisories/13203/http://securityreason.com/securityalert/3220http://www.frsirt.com/exploits/20041119.IESP2Unpatched.phphttp://www.kb.cert.org/vuls/id/743974http://www.securityfocus.com/bid/11686https://exchange.xforce.ibmcloud.com/vulnerabilities/18181http://archives.neohapsis.com/archives/bugtraq/2004-11/0260.htmlhttp://secunia.com/advisories/13203/http://securityreason.com/securityalert/3220http://www.frsirt.com/exploits/20041119.IESP2Unpatched.phphttp://www.kb.cert.org/vuls/id/743974http://www.securityfocus.com/bid/11686https://exchange.xforce.ibmcloud.com/vulnerabilities/18181
2004-11-16
Published