7.5

CVE-2004-1155

Exploit
Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.  NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Ie Version 5.0.1 Edition windows_2000
Microsoft ≫ Ie Version 5.0.1 Edition windows_95
Microsoft ≫ Ie Version 5.0.1 Edition windows_98
Microsoft ≫ Ie Version 5.0.1 Edition windows_nt_4.0
Microsoft ≫ Ie Version 5.2.3 Edition macintosh
Microsoft ≫ Ie Version 6.0 Update sp1
Microsoft ≫ Ie Version 6.0 Update sp2
Microsoft ≫ Ie Version 7.0 Update windows_xp_sp2
Microsoft ≫ Internet Explorer Version 5.0.1
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp1
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp2
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp3
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp4
Microsoft ≫ Internet Explorer Version 5.5
Microsoft ≫ Internet Explorer Version 5.5 Update preview
Microsoft ≫ Internet Explorer Version 5.5 Update sp1
Microsoft ≫ Internet Explorer Version 5.5 Update sp2
Microsoft ≫ Internet Explorer Version 6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.59% 0.957
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/13251/
http://secunia.com/advisories/22628
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
Vendor Advisory
http://secunia.com/secunia_research/2004-13/advisory/
http://www.securityfocus.com/archive/1/449917/100/0/threaded
http://www.securityfocus.com/bid/11855
Vendor Advisory
Exploit