5
CVSSv2

CVE-2004-2090

Published: 07/02/2004 Updated: 23/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Microsoft Internet Explorer 5.0.1 up to and including 6.0 allows remote malicious users to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 5.0.1

microsoft ie 6.0

microsoft internet explorer 5.5

microsoft internet explorer 6.0

Exploits

source: wwwsecurityfocuscom/bid/9611/info Microsoft Internet Explorer is prone to an issue that may permit a remote site to enumerate the existence of files on the client system This may be exploited via abuse of the VBScript LoadPicture method Exploitation of the weakness may assist in other attacks which depend on the attacker being ...