CVE-1999-0489: Critical severity Microsoft Windows NT vulnerability
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Microsoft Internet Explorer (MSHTML.DLL)to a version that resolves this vulnerability.Patch MS98-013
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0489?
CVE-1999-0489 has a severity rating that suggests a potential for significant impact on the security of affected systems.
How do I fix CVE-1999-0489?
To fix CVE-1999-0489, users should update to a more secure version of Internet Explorer that does not contain this vulnerability.
Which versions of Internet Explorer are affected by CVE-1999-0489?
CVE-1999-0489 specifically affects Internet Explorer 5.0 on Windows NT 4.0.
What type of attack is described in CVE-1999-0489?
CVE-1999-0489 describes an attack that allows a remote attacker to exploit a vulnerability in a file upload control through untrusted scripted paste.
Can CVE-1999-0489 be exploited remotely?
Yes, CVE-1999-0489 can be exploited remotely by an attacker under certain conditions.