First published: Tue Sep 14 2004(Updated: )
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya IP600 Media Servers | ||
Microsoft Internet Explorer | =6.0-sp1 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp3 | |
Internet Explorer | =5.0.1-sp4 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =6.0 | |
Avaya DEFINITY ONE Media Server | ||
Avaya S3400 | ||
Avaya S8100 | ||
Avaya Modular Messaging Message Storage Server | =1.1 | |
Avaya Modular Messaging Message Storage Server | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0841 has a high severity rating due to its potential for remote code execution.
To protect against CVE-2004-0841, users should upgrade to a secure version of Internet Explorer and avoid using outdated software.
CVE-2004-0841 affects multiple versions of Internet Explorer including 5.0.1, 5.5, and 6.0.
Microsoft released patches for CVE-2004-0841, and users should install these updates to mitigate the vulnerability.
CVE-2004-0841 exploits mousedown events and drag-and-drop actions to execute arbitrary code via the Popup.show method.