PT-2004-3277 · Microsoft · Internet Explorer

Published

2004-12-31

·

Updated

2021-07-23

·

CVE-2004-2383

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer versions 5.0 through 6.0
Description: The issue allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains. This can be achieved via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. It can be used in a spoofing scenario.
Recommendations: For Microsoft Internet Explorer versions 5.0 through 6.0, consider disabling Javascript in HTML documents outside a frameset to minimize the risk of exploitation. Restrict access to framesets that include target domains to prevent attackers from forcing the frameset to maintain focus.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2383

Affected Products

Internet Explorer