CVE-2005-3240
published 2005-12-31CVE-2005-3240: Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into…
PriorityP423medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
5.64%
92.1th percentile
Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious window.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| omnistar_interactive | omnistar_live | <= 5.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6h76-2q8f-58j3: Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user
ghsa_unreviewed·2022-05-01
CVE-2005-3240 [MEDIUM] CWE-362 GHSA-6h76-2q8f-58j3: Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user
Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious window.
GHSA
GHSA-7886-j39v-ch7f: SQL injection vulnerability in kb
ghsa_unreviewed·2022-05-01·CVSS 5.1
CVE-2005-3840 [MEDIUM] CWE-89 GHSA-7886-j39v-ch7f: SQL injection vulnerability in kb
SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://blogs.technet.com/msrc/archive/2006/02/13/419439.aspxhttp://secunia.com/advisories/18787http://securitytracker.com/id?1015049http://www.osvdb.org/2707http://www.securiteam.com/windowsntfocus/5MP0B0UHPA.htmlhttp://www.securityfocus.com/archive/1/424863/100/0/threadedhttp://www.securityfocus.com/archive/1/424940/100/0/threadedhttp://www.securityfocus.com/bid/16352http://www.vupen.com/english/advisories/2006/0553https://exchange.xforce.ibmcloud.com/vulnerabilities/24648http://blogs.technet.com/msrc/archive/2006/02/13/419439.aspxhttp://secunia.com/advisories/18787http://securitytracker.com/id?1015049http://www.osvdb.org/2707http://www.securiteam.com/windowsntfocus/5MP0B0UHPA.htmlhttp://www.securityfocus.com/archive/1/424863/100/0/threadedhttp://www.securityfocus.com/archive/1/424940/100/0/threadedhttp://www.securityfocus.com/bid/16352http://www.vupen.com/english/advisories/2006/0553https://exchange.xforce.ibmcloud.com/vulnerabilities/24648
2005-12-31
Published