First published: Wed Dec 15 2004(Updated: )
The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nortel IP Softphone 2050 | ||
Nortel Mobile Voice Client 2050 | ||
Nortel Optivity Telephony Manager | ||
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp3 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows Server 2003 | =enterprise | |
Microsoft Windows Server 2003 | =enterprise_64-bit | |
Microsoft Windows Server 2003 | =r2 | |
Microsoft Windows Server 2003 | =r2 | |
Microsoft Windows Server 2003 | =standard | |
Microsoft Windows Server 2003 | =web | |
Microsoft Windows 9x | =gold | |
Microsoft Windows 98 | ||
Microsoft Windows | ||
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft Windows XP | =gold | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1319 is classified as a medium severity vulnerability that allows for cross-domain script injection.
To fix CVE-2004-1319, it is recommended to patch your affected software, primarily by upgrading to a secure version of the software that addresses this vulnerability.
CVE-2004-1319 affects various Microsoft Windows operating systems including Windows XP and Windows Server 2003 as well as Nortel products.
CVE-2004-1319 facilitates cross-site scripting (XSS) attacks by allowing remote attackers to inject arbitrary web scripts.
Users and organizations utilizing vulnerable versions of Microsoft Windows and Nortel software are at risk from CVE-2004-1319.