Oval Definition:oval:org.mitre.oval:def:1186
Revision Date:2011-05-16Version:48
Title:IE .chm Directory Traversal Windows XP Vulnerability
Description:Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2003-1041
Platform(s):Microsoft Windows XP
Product(s):HTML Help Facility
Definition Synopsis
  • Software section
  • the version of itss.dll is less than 5.2.3790.185
  • AND NOT the patch kb840315 is installed
  • AND Windows XP (sp1 or earlier) is installed
  • Windows XP is installed
  • AND NOT Win2K/XP/2003 service pack 2 (or later) is installed
  • AND Configuration section
  • NOT HTML Help is registered
  • BACK