Oval Definition:oval:org.mitre.oval:def:7496
Revision Date:2014-02-24Version:44
Title:IE v6.0,SP2 for Server 2003 Similar Method Name Redirection Cross Domain Vulnerability
Description:Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2004-0727
Platform(s):Microsoft Windows Server 2003
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • Software section
  • Internet Explorer 6 Service Pack 2 for XP is installed
  • AND a vulnerable version of mshtml.dll exisits
  • machine has followed the GDR update path and mshtml.dll is less than 6.0.2900.2523
  • OR machine has followed the QFE update path and mshtml.dll is less than 6.0.2900.2524
  • AND NOT the patch kb834707 is installed (Installed Components key)
  • AND Configuration section
  • ActiveX controls and active scripting are enabled
  • current user settings are being used and ActiveX controls and active scripting are enabled
  • NOT use machine settings rather than individual user settings
  • AND ActiveX controls are enabled for the current user
  • AND active scripting is enabled for the current user
  • OR local machine settings are being used and ActiveX controls and active scripting are enabled
  • use machine settings rather than individual user settings
  • AND ActiveX controls are enabled for the local machine
  • AND active scripting is enabled for the local machine
  • BACK