Vulnerabilities > CVE-2001-0154 - Unspecified vulnerability in Microsoft Internet Explorer
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
Vulnerable Configurations
Nessus
NASL family | Backdoors |
NASL id | BUGBEAR.NASL |
description | The BugBear backdoor is listening on this port. An attacker may connect to it to retrieve secret information such as passwords, credit card numbers, etc. The BugBear worm includes a keylogger and can kill antivirus and firewall software. It propagates through email and open Windows shares. Depending on the antivirus vendor, it is known as Tanatos, I-Worm.Tanatos, NATOSTA.A, W32/Bugbear-A, Tanatos, W32/Bugbear@MM, WORM_BUGBEAR.A, Win32.BugBear... |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11135 |
published | 2002-10-03 |
reporter | This script is Copyright (C) 2002-2018 Michel Arboi & Thomas Reinke |
source | https://www.tenable.com/plugins/nessus/11135 |
title | Bugbear Worm Detection |
code |
|
Oval
accepted | 2016-02-19T10:00:00.000-04:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
description | HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:141 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||||||||||||||||||||||||||
submitted | 2003-07-18T12:00:00.000-04:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
title | Microsoft Internet Explorer MIME Hack | ||||||||||||||||||||||||||||||||||||||||||||||||||||
version | 73 |
References
- http://marc.info/?l=bugtraq&m=98596775905044&w=2
- http://marc.info/?l=bugtraq&m=98596775905044&w=2
- http://securitytracker.com/id?1001197
- http://securitytracker.com/id?1001197
- http://www.cert.org/advisories/CA-2001-06.html
- http://www.cert.org/advisories/CA-2001-06.html
- http://www.ciac.org/ciac/bulletins/l-066.shtml
- http://www.ciac.org/ciac/bulletins/l-066.shtml
- http://www.osvdb.org/7806
- http://www.osvdb.org/7806
- http://www.securityfocus.com/bid/2524
- http://www.securityfocus.com/bid/2524
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-020
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-020
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6306
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6306
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A141
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A141