CVE-2004-1376: Medium severity Microsoft Internet Explorer vulnerability
Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1376?
CVE-2004-1376 is rated as a medium severity vulnerability due to its potential to allow an attacker to overwrite arbitrary files.
How do I fix CVE-2004-1376?
To mitigate CVE-2004-1376, upgrade to a later version of Internet Explorer or apply security patches provided by Microsoft.
Which versions of Internet Explorer are affected by CVE-2004-1376?
CVE-2004-1376 affects Internet Explorer versions 5.01, 5.5, and 6.0.
What does CVE-2004-1376 exploit?
CVE-2004-1376 exploits a directory traversal vulnerability allowing remote FTP servers to manipulate files on a user's system.
Can CVE-2004-1376 be exploited remotely?
Yes, CVE-2004-1376 can be exploited remotely by a malicious FTP server using specially crafted filenames.