PT-2004-2242 · Microsoft · Internet Explorer+1

Publicado

2004-12-15

·

Atualizado

2019-04-30

·

CVE-2004-1319

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: DHTML Edit Control (dhtmled.ocx) version 6.0.2900.2180
Description: The issue allows remote attackers to inject arbitrary web script into other domains. This is achieved by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript. This has been demonstrated in Internet Explorer.
Recommendations: For version 6.0.2900.2180, consider restricting the use of the DHTML Edit Control to minimize the risk of exploitation. As a temporary workaround, avoid using the execScript function until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1319

Produtos afetados

Dhtml Edit Control
Internet Explorer