Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2004-0839

Description

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".

POC

Reference

- http://marc.info/?l=bugtraq&m=109336221826652&w=2

- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038

Github

No PoCs found on GitHub currently.