Vulnerabilities > CVE-2005-2117 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 4 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS05-049.NASL |
description | The remote version of Windows contains a version of the Windows Shell that has several vulnerabilities. An attacker may exploit these vulnerabilities by : - Sending a malformed .lnk file a to user on the remote host to trigger an overflow. - Sending a malformed HTML document to a user on the remote host and have him view it in the Windows Explorer preview pane. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20002 |
published | 2005-10-11 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20002 |
title | MS05-049: Vulnerabilities in Windows Shell Could Allow Remote Code Execution (900725) |
code |
|
Oval
accepted | 2011-05-16T04:00:47.926-04:00 | ||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||
contributors |
| ||||||||||||||||||||
description | Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code. | ||||||||||||||||||||
family | windows | ||||||||||||||||||||
id | oval:org.mitre.oval:def:1291 | ||||||||||||||||||||
status | accepted | ||||||||||||||||||||
submitted | 2005-10-12T12:00:00.000-04:00 | ||||||||||||||||||||
title | Windows Explorer Web View Script Injection Vulnerability | ||||||||||||||||||||
version | 69 |
References
- http://www.us-cert.gov/cas/techalerts/TA05-284A.html
- http://www.securityfocus.com/bid/15064
- http://secunia.com/advisories/17168
- http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
- http://secunia.com/advisories/17172
- http://secunia.com/advisories/17223
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1291
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-049