First published: Sat Feb 07 2004(Updated: )
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp3 | |
Internet Explorer | =5.0.1-sp4 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2090 has been classified as a moderate severity vulnerability.
CVE-2004-2090 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method.
CVE-2004-2090 affects Microsoft Internet Explorer versions from 5.0.1 through 6.0, including service packs.
To mitigate CVE-2004-2090, users should upgrade to a supported version of Internet Explorer or disable VBScript.
There is no specific patch for CVE-2004-2090, so upgrading to a later version of Internet Explorer is recommended.