Oval Definition:oval:org.mitre.oval:def:7448
Revision Date:2014-02-24Version:46
Title:IE v5.5,SP2 Similar Method Name Redirection Cross Domain Vulnerability
Description:Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2004-0727
Platform(s):Microsoft Windows 2000
Microsoft Windows 98
Microsoft Windows NT
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • Software section
  • Internet Explorer 5.5 Service Pack 2 is installed
  • AND the version of mshtml.dll is less than 5.50.4945.2800
  • AND NOT the patch kb834707 is installed (Installed Components key)
  • AND Configuration section
  • ActiveX controls and active scripting are enabled
  • current user settings are being used and ActiveX controls and active scripting are enabled
  • NOT use machine settings rather than individual user settings
  • AND ActiveX controls are enabled for the current user
  • AND active scripting is enabled for the current user
  • OR local machine settings are being used and ActiveX controls and active scripting are enabled
  • use machine settings rather than individual user settings
  • AND ActiveX controls are enabled for the local machine
  • AND active scripting is enabled for the local machine
  • BACK