CVE-2004-0526
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/08/2004
Last modified:
03/04/2025
Description
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:outlook:97:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:outlook:98:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:outlook:2000:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:outlook:2000:sp2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2004-05/0161.html
- http://marc.info/?l=bugtraq&m=108422905510713&w=2
- http://www.kurczaba.com/securityadvisories/0405132poc.htm
- http://www.securityfocus.com/bid/10308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16102
- http://archives.neohapsis.com/archives/bugtraq/2004-05/0161.html
- http://marc.info/?l=bugtraq&m=108422905510713&w=2
- http://www.kurczaba.com/securityadvisories/0405132poc.htm
- http://www.securityfocus.com/bid/10308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16102



