CVE-2004-1331
CVE-2004-1331
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://archives.neohapsis.com/archives/bugtraq/2004-11/0260.htmlhttp://secunia.com/advisories/13203/http://securityreason.com/securityalert/3220https://exchange.xforce.ibmcloud.com/vulnerabilities/18181http://www.frsirt.com/exploits/20041119.IESP2Unpatched.phphttp://www.kb.cert.org/vuls/id/743974http://www.securityfocus.com/bid/11686