Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
2004-08-18T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | avaya | ip600_media_servers | * | Yes |
Application | microsoft | ie | 6.0 | Yes |
Application | microsoft | ie | 6.0 | Yes |
Application | microsoft | internet_explorer | 5.0.1 | Yes |
Application | microsoft | internet_explorer | 5.0.1 | Yes |
Application | microsoft | internet_explorer | 5.0.1 | Yes |
Application | microsoft | internet_explorer | 5.0.1 | Yes |
Application | microsoft | internet_explorer | 5.0.1 | Yes |
Application | microsoft | internet_explorer | 5.5 | Yes |
Application | microsoft | internet_explorer | 5.5 | Yes |
Application | microsoft | internet_explorer | 5.5 | Yes |
Application | microsoft | internet_explorer | 6.0 | Yes |
Hardware | avaya | definity_one_media_server | * | Yes |
Hardware | avaya | s3400 | * | Yes |
Hardware | avaya | s8100 | * | Yes |
Application | nortel | ip_softphone_2050 | * | Yes |
Application | nortel | mobile_voice_client_2050 | * | Yes |
Application | nortel | optivity_telephony_manager | * | Yes |
Application | nortel | symposium_web_centre_portal | * | Yes |
Application | nortel | symposium_web_client | * | Yes |
Operating System | avaya | modular_messaging_message_storage_server | 1.1 | Yes |
Operating System | avaya | modular_messaging_message_storage_server | 2.0 | Yes |
Operating System | microsoft | windows_2000 | * | Yes |
Operating System | microsoft | windows_2000 | * | Yes |
Operating System | microsoft | windows_2000 | * | Yes |
Operating System | microsoft | windows_2000 | * | Yes |
Operating System | microsoft | windows_2000 | * | Yes |
Operating System | microsoft | windows_2003_server | enterprise | Yes |
Operating System | microsoft | windows_2003_server | enterprise_64-bit | Yes |
Operating System | microsoft | windows_2003_server | r2 | Yes |
Operating System | microsoft | windows_2003_server | r2 | Yes |
Operating System | microsoft | windows_2003_server | standard | Yes |
Operating System | microsoft | windows_2003_server | web | Yes |
Operating System | microsoft | windows_98 | * | Yes |
Operating System | microsoft | windows_98se | * | Yes |
Operating System | microsoft | windows_me | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Operating System | microsoft | windows_xp | * | Yes |