[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-1319Date: (C)2004-12-15   (M)2023-12-22


The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-11950
SECUNIA-13482
http://archives.neohapsis.com/archives/bugtraq/2004-12/0167.html
MS05-013
TA05-039A
VU#356600
http://freehost07.websamba.com/greyhats/abusiveparent-discussion.htm
ie-dhtml-xss(18504)
oval:org.mitre.oval:def:1114
oval:org.mitre.oval:def:1701
oval:org.mitre.oval:def:3464
oval:org.mitre.oval:def:3851
oval:org.mitre.oval:def:4758

CPE    16
cpe:/a:nortel:mobile_voice_client_2050
cpe:/o:microsoft:windows_xp::sp1:media_center
cpe:/o:microsoft:windows_xp::sp2:media_center
cpe:/o:microsoft:windows_98::gold
...
OVAL    5
oval:org.mitre.oval:def:1114
oval:org.mitre.oval:def:3851
oval:org.mitre.oval:def:3464
oval:org.mitre.oval:def:4758
...

© SecPod Technologies