PT-2004-3277 · Microsoft · Internet Explorer
Published
2004-12-31
·
Updated
2021-07-23
·
CVE-2004-2383
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Internet Explorer versions 5.0 through 6.0
Description:
The issue allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains. This can be achieved via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. It can be used in a spoofing scenario.
Recommendations:
For Microsoft Internet Explorer versions 5.0 through 6.0, consider disabling Javascript in HTML documents outside a frameset to minimize the risk of exploitation. Restrict access to framesets that include target domains to prevent attackers from forcing the frameset to maintain focus.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer