CVE Database
/

CVE-2004-1319

Back to search

CVE-2004-1319

Published: Jan 6, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.

VendorProductVersions

n/a

n/a

affected
n/a

References

13482
third-party-advisory
x_refsource_SECUNIA
ie-dhtml-xss(18504)
vdb-entry
x_refsource_XF
TA05-039A
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:3851
vdb-entry
signature
x_refsource_OVAL
11950
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:1114
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:3464
vdb-entry
signature
x_refsource_OVAL
MS05-013
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:4758
vdb-entry
signature
x_refsource_OVAL
VU#356600
third-party-advisory
x_refsource_CERT-VN
oval:org.mitre.oval:def:1701
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now