CVE-2004-1331
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/11/2004
Last modified:
03/04/2025
Description
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.
Impact
Base Score 2.0
2.60
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6.0:sp2:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2004-11/0260.html
- http://secunia.com/advisories/13203/
- http://securityreason.com/securityalert/3220
- http://www.frsirt.com/exploits/20041119.IESP2Unpatched.php
- http://www.kb.cert.org/vuls/id/743974
- http://www.securityfocus.com/bid/11686
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18181
- http://archives.neohapsis.com/archives/bugtraq/2004-11/0260.html
- http://secunia.com/advisories/13203/
- http://securityreason.com/securityalert/3220
- http://www.frsirt.com/exploits/20041119.IESP2Unpatched.php
- http://www.kb.cert.org/vuls/id/743974
- http://www.securityfocus.com/bid/11686
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18181