Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by wottapoop.html.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Internet_explorer | Microsoft | 5.5 | 5.5 |
Internet_explorer | Microsoft | 5.5 | 5.5 |
Ip600_media_servers | Avaya | * | * |
Internet_explorer | Microsoft | 5.0.1 | 5.0.1 |
Internet_explorer | Microsoft | 5.5 | 5.5 |
Internet_explorer | Microsoft | 6.0 | 6.0 |
Internet_explorer | Microsoft | 5.0.1 | 5.0.1 |
Internet_explorer | Microsoft | 5.0.1 | 5.0.1 |
Ie | Microsoft | 6.0 | 6.0 |
Ie | Microsoft | 6.0 | 6.0 |
Internet_explorer | Microsoft | 5.0.1 | 5.0.1 |
Definity_one_media_server | Avaya | * | * |
S8100 | Avaya | * | * |
S3400 | Avaya | * | * |
Internet_explorer | Microsoft | 5.0.1 | 5.0.1 |