Oval Definition:
oval:org.mitre.oval:def:123
Revision Date
:
2014-02-24
Version
:
45
Title
:
IE Improper Object Tag Handling
Description
:
Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2003-0809
Platform(s)
:
Microsoft Windows 2000
Product(s)
:
Definition Synopsis
Software section
Internet Explorer 6.0 or IE 6.0 SP1 is installed
Internet Explorer 6 is installed
OR
Internet Explorer 6 Service Pack 1 is installed
AND
the version of mshtml.dll is less than 6.0.2800.1264
AND
NOT
the patch q828750 is installed (Installed Components key)
AND
NOT
the patch q824145 is installed (Installed Components key)
AND
Configuration section
ActiveX controls are enabled
current user settings are being used and ActiveX controls are enabled
NOT
use machine settings rather than individual user settings
AND
ActiveX controls are enabled for the current user
OR
local machine settings are being used and ActiveX controls are enabled
use machine settings rather than individual user settings
AND
ActiveX controls are enabled for the local machine
AND
.hta applications are enabled
BACK