CVE-2004-0549
Summary
| CVE | CVE-2004-0549 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-08-06 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Explorer | All | All | All | All |
| Application | Microsoft | Internet Explorer | 5.01 | All | All | All |
| Application | Microsoft | Internet Explorer | 5.5 | All | All | All |
| Application | Microsoft | Internet Explorer | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 62.131.86.111/analysis.htm | af854a3a-2127-422b-91ae-364da2661108 | 62.131.86.111 | |
| US-CERT Technical Cyber Security Alert TA04-163A -- Cross-Domain Redirect Vulnerability in Internet Explorer | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Patch, Third Party Advisory, US Government Resource |
| Neohapsis Archives - Full Disclosure List - #0031 - [Full-Disclosure] 180 Solutions Exploits and Toolbars Hacking Patched Users(I.E Exploits) | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| US-CERT Technical Cyber Security Alert TA04-184A -- Internet Explorer Update to Disable ADODB.Stream ActiveX Control | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Page not found - Umbrella | af854a3a-2127-422b-91ae-364da2661108 | umbrella.name | |
| archives.neohapsis.com/archives/fulldisclosure/2004-06/0104.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| Microsoft Security Bulletin MS04-025 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| 'JS.Scob.Trojan Source Code ...' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'IE/0DAY -> Insider Prototype' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| US-CERT Technical Cyber Security Alert TA04-212A -- Critical Vulnerabilities in Microsoft Windows | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| US-CERT Vulnerability Note VU#713878 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.