CVE Vulnerabilities

CVE-2004-2090

Published: Feb 07, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.

Affected Software

NameVendorStart VersionEnd Version
IeMicrosoft6.0-sp1 (including)6.0-sp1 (including)
Internet_explorerMicrosoft5.0.1 (including)5.0.1 (including)
Internet_explorerMicrosoft5.0.1-sp1 (including)5.0.1-sp1 (including)
Internet_explorerMicrosoft5.0.1-sp2 (including)5.0.1-sp2 (including)
Internet_explorerMicrosoft5.0.1-sp3 (including)5.0.1-sp3 (including)
Internet_explorerMicrosoft5.0.1-sp4 (including)5.0.1-sp4 (including)
Internet_explorerMicrosoft5.5 (including)5.5 (including)
Internet_explorerMicrosoft5.5-sp1 (including)5.5-sp1 (including)
Internet_explorerMicrosoft5.5-sp2 (including)5.5-sp2 (including)
Internet_explorerMicrosoft6.0 (including)6.0 (including)

References