7.5
CVSSv2

CVE-2003-1041

Published: 14/06/2004 Updated: 23/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Internet Explorer 5.x and 6.0 allows remote malicious users to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 5

microsoft internet explorer 5.5

microsoft ie 6.0

microsoft ie 6

microsoft internet explorer 6.0

Exploits

source: wwwsecurityfocuscom/bid/9320/info Microsoft Windows is prone to a security flaw in the implementation of the showHelp() function Microsoft previously released patches that provide security measures to prevent abuse of the showHelp() method to reference local compiled help files (CHM) from within a web page This initial problem ...