Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2004-0549
Description:The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2004-0549
Bugtraq: 20040621 IE/0DAY -> Insider Prototype (Google Search)
http://marc.info/?l=bugtraq&m=108786396622284&w=2
Bugtraq: 20040628 JS.Scob.Trojan Source Code ... (Google Search)
http://marc.info/?l=bugtraq&m=108852642021426&w=2
Cert/CC Advisory: TA04-163A
http://www.us-cert.gov/cas/techalerts/TA04-163A.html
Cert/CC Advisory: TA04-184A
http://www.us-cert.gov/cas/techalerts/TA04-184A.html
Cert/CC Advisory: TA04-212A
http://www.us-cert.gov/cas/techalerts/TA04-212A.html
CERT/CC vulnerability note: VU#713878
http://www.kb.cert.org/vuls/id/713878
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0031.html
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0104.html
http://62.131.86.111/analysis.htm
http://umbrella.name/originalvuln/msie/InsiderPrototype/
Microsoft Security Bulletin: MS04-025
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-025
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1133
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A207
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A241
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A519
XForce ISS Database: ie-location-restriction-bypass(16348)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16348




© 1998-2025 E-Soft Inc. All rights reserved.