New Search

IE v5.01SP4 Drag-and-Drop Code Execution Vulnerability

oval:org.mitre.oval:def:4152

Internet Explorer in Windows XP SP2 and other versions including 5.01 and 5.5 allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior popup windows and drag-and-drop capabilities to drop the program in the local startup folder as demonstrated by "wottapoop.html".

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows 2000
Class:
vulnerability
Reference(s):
  • CVE-2004-0839
Product(s):
  • Microsoft Internet Explorer