7.5
CVSSv2

CVE-2003-0838

Published: 17/11/2003 Updated: 23/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Internet Explorer allows remote malicious users to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 5.0.1

microsoft internet explorer 6.0

microsoft ie 6.0

microsoft internet explorer 5.5

Exploits

source: wwwsecurityfocuscom/bid/8556/info Internet Explorer does not properly handle object types, when rendering malicious popup windows This may result in the possibility of the execution of malicious software The problem occurs when Internet Explorer receives a response from the server when a malicious popup window containing an obj ...