5
CVSSv2

CVE-2004-1319

Published: 15/12/2004 Updated: 30/04/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The DHTML Edit Control (dhtmled.ocx) allows remote malicious users to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 2000

microsoft windows 2003 server web

microsoft windows 98

microsoft windows 98se

microsoft windows xp

microsoft windows 2003 server r2

microsoft windows 2003 server standard

microsoft windows 2003 server enterprise_64-bit

nortel ip softphone 2050

nortel mobile voice client 2050

nortel optivity telephony manager

microsoft windows 2003 server enterprise

microsoft windows me