First published: Mon May 17 1999(Updated: )
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | =4.0 | |
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0489 has a severity rating that suggests a potential for significant impact on the security of affected systems.
To fix CVE-1999-0489, users should update to a more secure version of Internet Explorer that does not contain this vulnerability.
CVE-1999-0489 specifically affects Internet Explorer 5.0 on Windows NT 4.0.
CVE-1999-0489 describes an attack that allows a remote attacker to exploit a vulnerability in a file upload control through untrusted scripted paste.
Yes, CVE-1999-0489 can be exploited remotely by an attacker under certain conditions.