CVE-2004-1155: High severity microsoft ie vulnerability
Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1155?
CVE-2004-1155 has been classified as a moderate severity vulnerability.
How do I fix CVE-2004-1155?
To fix CVE-2004-1155, update your Internet Explorer to a version that is not affected, such as versions beyond 6.0.
Which software versions are affected by CVE-2004-1155?
CVE-2004-1155 affects Internet Explorer versions 5.0.1 up to 6.0 service packs 1 and 2.
What type of attack does CVE-2004-1155 permit?
CVE-2004-1155 allows remote attackers to spoof websites by injecting content into pop-up windows.
What are the potential impacts of CVE-2004-1155?
The impact of CVE-2004-1155 includes user data exposure and phishing risks due to site spoofing.