Vulnerabilities > CVE-2004-0841

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
microsoft
avaya
exploit available

Summary

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."

Exploit-Db

descriptionMicrosoft Internet Explorer 5.0.1 Popup.show Mouse Event Hijacking Vulnerability. CVE-2004-0841. Remote exploit for windows platform
idEDB-ID:24266
last seen2016-02-02
modified2004-07-12
published2004-07-12
reporterPaul
sourcehttps://www.exploit-db.com/download/24266/
titleMicrosoft Internet Explorer 5.0.1 Popup.show Mouse Event Hijacking Vulnerability

Oval

  • accepted2014-02-24T04:03:13.349-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:2611
    statusaccepted
    submitted2004-10-25T04:00:00.000-04:00
    titleIE v6.0 HijackClick 3 / Script in Image Tag File Download Vulnerability
    version68
  • accepted2014-02-24T04:03:18.632-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:4363
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleIE v5.01, SP3 HijackClick 3 / Script in Image Tag File Download Vulnerability
    version67
  • accepted2014-02-24T04:03:23.531-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:5620
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleIE v6.0 for 2003, SP3 HijackClick 3 / Script in Image Tag File Download Vulnerability
    version68
  • accepted2014-02-24T04:03:24.130-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:6031
    statusaccepted
    submitted2004-10-25T07:54:00.000-04:00
    titleIE v5.5, SP2 HijackClick 3 / Script in Image Tag File Download Vulnerability
    version67
  • accepted2014-02-24T04:03:24.192-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:6048
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleIE v5.01, SP4 HijackClick 3 / Script in Image Tag File Download Vulnerability
    version67
  • accepted2014-02-24T04:03:27.894-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:8077
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleIE v6.0, SP1 HijackClick 3 / Script in Image Tag File Download Vulnerability
    version68