CVE-2004-0380

Loading...

General

Score:10.0/10.0
Severity:High
Category:N/A
Exploit:Available

Impact Metrics

Confidentiality:Complete
Integrity:Complete
Availability:Complete

Exploitability Metrics

Access Vector:Network
Access Complexity:Low
Authentication:None

Published on 04/05/04 - Updated on 03/05/18

Description

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."

Category:

There is insufficient information about the issue to classify it; details are unknown or unspecified.

Security Notices

US National Vulnerability DatabaseCVE-2004-0380

Exploits

Exploit-DBEDB-23400, EDB-23401, EDB-23695
SecurityFocusBID-9105, BID-9658

Relative technologies

VendorProduct
microsoftoutlook_express

Share this vulnerability with:

Twitter Facebook LinkedIn Mail