imPC@ndo IT

Tracker / CVE-2004-1050

CVE-2004-1050

High 10.0

Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."

Affected products and versions

avaya definity_one_media_server
avaya ip600_media_servers
avaya modular_messaging_message_storage_server
avaya s3400
avaya s8100
microsoft ie
microsoft internet_explorer

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References