MEDIUM · 5.0

CVE-2004-0839

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavi...

Vulnerability Description

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
AvayaIp600 Media ServersAll versions
MicrosoftIe6.0
MicrosoftInternet Explorer5.0.1
AvayaDefinity One Media ServerAll versions
AvayaS3400All versions
AvayaS8100All versions
NortelIp Softphone 2050All versions
NortelMobile Voice Client 2050All versions
NortelOptivity Telephony ManagerAll versions
NortelSymposium Web Centre PortalAll versions
NortelSymposium Web ClientAll versions
AvayaModular Messaging Message Storage Server1.1
MicrosoftWindows 2000All versions
MicrosoftWindows 2003 Serverenterprise
MicrosoftWindows 98All versions
MicrosoftWindows 98SeAll versions
MicrosoftWindows MeAll versions
MicrosoftWindows XpAll versions

References

FAQ

What is CVE-2004-0839?

CVE-2004-0839 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavi...

How severe is CVE-2004-0839?

CVE-2004-0839 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0839?

Check the references section above for vendor advisories and patch information. Affected products include: Avaya Ip600 Media Servers, Microsoft Ie, Microsoft Internet Explorer, Avaya Definity One Media Server, Avaya S3400.