CVE-2004-1331: Low severity Microsoft ie vulnerability
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1331?
CVE-2004-1331 is considered a critical vulnerability that poses significant risk to users of Internet Explorer 6.0 SP1 and SP2.
How do I fix CVE-2004-1331?
To mitigate CVE-2004-1331, upgrading to a newer version of Internet Explorer or applying the relevant security patches provided by Microsoft is recommended.
Who is affected by CVE-2004-1331?
CVE-2004-1331 affects users of Microsoft Internet Explorer 6.0, specifically those using Service Packs 1 and 2.
What actions can attackers perform using CVE-2004-1331?
Attackers exploiting CVE-2004-1331 can bypass security warnings and save arbitrary files on the victim's system.
Is there a workaround for CVE-2004-1331?
Disabling the execution of scripts in Internet Explorer can serve as a temporary workaround to reduce the risk from CVE-2004-1331.