← Back

CVE-2004-1155

nvd nist
Published: Dec 31, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.

Affected (18)

2 products
Ie
Internet Explorer
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 5.0.1
Version 5.0.1
Version 5.0.1
Version 5.0.1
Version 5.2.3
Version 6.0 sp1
Version 6.0 sp2
Version 7.0 windows_xp_sp2
Microsoft
Version 5.0.1
Version 5.0.1 sp1
Version 5.0.1 sp2
Version 5.0.1 sp3
Version 5.0.1 sp4
Version 5.5
Version 5.5 preview
Version 5.5 sp1
Version 5.5 sp2
Version 6.0

References (12)

Source: cve@mitre.org
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory

Timeline

No history available yet.