[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-0054Date: (C)2005-05-02   (M)2023-12-22


Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.1
Exploit Score: 4.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://marc.info/?l=bugtraq&m=110796851002781&w=2
MS05-014
TA05-039A
VU#580299
ie-file-url-encode(19214)
oval:org.mitre.oval:def:1308
oval:org.mitre.oval:def:1736
oval:org.mitre.oval:def:3060
oval:org.mitre.oval:def:3196
oval:org.mitre.oval:def:3586

OVAL    5
oval:org.mitre.oval:def:1308
oval:org.mitre.oval:def:1736
oval:org.mitre.oval:def:3196
oval:org.mitre.oval:def:3060
...

© SecPod Technologies