CVE-2004-0839 - CVE House
Back to Database
Status published Medium CVE-2004-0839

Internet Explorer in Windows XP SP2, and other versions including...

Vulnerability Description

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0839

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ip600 media servers, ie, internet explorer, definity one media server, s3400, s8100, ip softphone 2050, mobile voice client 2050, optivity telephony manager, symposium web centre portal, symposium web client, modular messaging message storage server, windows 2000, windows 2003 server, windows 98, windows 98se, windows me, windows xp
Vulnerable Versions:
6.0, 5.0.1, 5.5, 1.1, 2.0, enterprise, enterprise_64-bit, r2, standard, web

Timeline

Official Publish: September 14th, 2004
Last Modified: August 8th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.