CVE Vulnerabilities

CVE-2004-1319

Published: Dec 15, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by AbusiveParent in Internet Explorer 6.0.2900.2180.

Affected Software

NameVendorStart VersionEnd Version
Ip_softphone_2050Nortel**
Mobile_voice_client_2050Nortel**
Optivity_telephony_managerNortel**
Windows_2000Microsoft**
Windows_2003_serverMicrosoftenterprise (including)enterprise (including)
Windows_2003_serverMicrosoftenterprise_64-bit (including)enterprise_64-bit (including)
Windows_2003_serverMicrosoftr2 (including)r2 (including)
Windows_2003_serverMicrosoftstandard (including)standard (including)
Windows_2003_serverMicrosoftweb (including)web (including)
Windows_98Microsoft**
Windows_98seMicrosoft**
Windows_meMicrosoft**
Windows_xpMicrosoft**

References