Vulnerabilities > CVE-2004-0727 - Unspecified vulnerability in Microsoft Internet Explorer 6.0.2800.1106

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
exploit available

Summary

Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."

Vulnerable Configurations

Part Description Count
Application
Microsoft
1

Exploit-Db

descriptionMicrosoft Internet Explorer 5.0.1 JavaScript Method Assignment Cross-Domain Scripting Vulnerability. CVE-2004-0727. Remote exploit for windows platform
idEDB-ID:24265
last seen2016-02-02
modified2004-07-12
published2004-07-12
reporterPaul
sourcehttps://www.exploit-db.com/download/24265/
titleMicrosoft Internet Explorer 5.0.1 JavaScript Method Assignment Cross-Domain Scripting Vulnerability

Oval

  • accepted2014-02-24T04:03:19.508-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionMicrosoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:4702
    statusaccepted
    submitted2004-10-19T07:27:00.000-04:00
    titleIE v5.01,SP4 Similar Method Name Redirection Cross Domain Vulnerability
    version67
  • accepted2014-02-24T04:03:25.399-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionMicrosoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:6829
    statusaccepted
    submitted2004-10-19T07:37:00.000-04:00
    titleIE v6.0,SP1 Similar Method Name Redirection Cross Domain Vulnerability
    version68
  • accepted2014-02-24T04:03:25.745-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionMicrosoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:7084
    statusaccepted
    submitted2004-10-19T07:22:00.000-04:00
    titleIE v5.01,SP3 Similar Method Name Redirection Cross Domain Vulnerability
    version67
  • accepted2014-02-24T04:03:26.407-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameAndrew Simmons
      organizationMessageLabs
    • nameTodd Dolinsky
      organizationHewlett-Packard
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionMicrosoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:7448
    statusaccepted
    submitted2004-10-19T07:31:00.000-04:00
    titleIE v5.5,SP2 Similar Method Name Redirection Cross Domain Vulnerability
    version69
  • accepted2014-02-24T04:03:26.550-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameJohn Hoyland
      organizationCentennial Software
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionMicrosoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:7496
    statusaccepted
    submitted2004-10-19T07:40:00.000-04:00
    titleIE v6.0,SP2 for Server 2003 Similar Method Name Redirection Cross Domain Vulnerability
    version67
  • accepted2014-02-24T04:03:27.521-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionMicrosoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:7906
    statusaccepted
    submitted2004-10-19T04:00:00.000-04:00
    titleIE v6.0 Similar Method Name Redirection Cross Domain Vulnerability
    version68