First published: Wed Dec 15 2004(Updated: )
The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp1 | |
Nortel Optivity Telephony Manager | ||
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 2003 Server | =enterprise | |
Microsoft Windows 2003 Server | =enterprise_64-bit | |
Microsoft Windows XP | =gold | |
Microsoft Windows 2000 | ||
Microsoft Windows XP | ||
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 98SE | ||
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2000 | =sp1 | |
Nortel Ip Softphone 2050 | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows Me | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows 98 | =gold | |
Nortel Mobile Voice Client 2050 | ||
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2000 | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.