First published: Wed Aug 18 2004(Updated: )
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Definity One Media Server | ||
Microsoft Ie | =6.0-sp1 | |
Avaya S8100 | ||
Avaya Ip600 Media Servers | ||
Microsoft Ie | =6.0-sp2 | |
Avaya S3400 | ||
Microsoft Internet Explorer | =5.5-sp2 | |
Microsoft Internet Explorer | =5.0.1 | |
Microsoft Internet Explorer | =5.0.1-sp2 | |
Microsoft Internet Explorer | =5.0.1-sp3 | |
Microsoft Internet Explorer | =5.0.1-sp4 | |
Microsoft Internet Explorer | =5.0.1-sp1 | |
Microsoft Internet Explorer | =5.5 | |
Microsoft Internet Explorer | =5.5-sp1 | |
Microsoft Internet Explorer | =6.0 | |
Microsoft Windows XP | =sp1 | |
Nortel Optivity Telephony Manager | ||
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 2003 Server | =enterprise | |
Microsoft Windows 2003 Server | =enterprise_64-bit | |
Microsoft Windows XP | =gold | |
Microsoft Windows 2000 | ||
Microsoft Windows XP | ||
Avaya Modular Messaging Message Storage Server | =2.0 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 98SE | ||
Microsoft Windows 2000 | =sp2 | |
Nortel Symposium Web Client | ||
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2000 | =sp1 | |
Nortel Ip Softphone 2050 | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows Me | ||
Nortel Symposium Web Centre Portal | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows XP | =sp2 | |
Avaya Modular Messaging Message Storage Server | =1.1 | |
Microsoft Windows 98 | =gold | |
Nortel Mobile Voice Client 2050 | ||
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2000 | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.