Vulnerability Name: | CVE-2003-1041 (CCN-14105) | ||||||||||||||||||||
Assigned: | 2003-12-30 | ||||||||||||||||||||
Published: | 2003-12-30 | ||||||||||||||||||||
Updated: | 2021-07-23 | ||||||||||||||||||||
Summary: | Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. Note: this bug may overlap CVE-2004-0475. | ||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Dec 29 2003 - 21:57:49 CST IE 5.x-6.0 allows executing arbitrary programs using showHelp() Source: MITRE Type: CNA CVE-2003-1041 Source: CCN Type: CIAC Information Bulletin 0-182 Microsoft Vulnerability in HTML Help Could Allow Code Execution Source: CCN Type: US-CERT VU#187196 Microsoft Windows fails to properly process showHelp URLs Source: CERT-VN Type: US Government Resource VU#187196 Source: CCN Type: Microsoft Security Bulletin MS04-023 Vulnerability in HTML Help Could Allow Code Execution (840315) Source: CCN Type: Microsoft Security Bulletin MS05-026 Vulnerability in HTML Help Could Allow Remote Code Execution (896358) Source: BUGTRAQ Type: Exploit, Vendor Advisory 20031230 IE 5.x-6.0 allows executing arbitrary programs using showHelp() Source: BID Type: Exploit, Vendor Advisory 9320 Source: CCN Type: BID-9320 Microsoft Windows showHelp CHM File Execution Weakness Source: CERT Type: Third Party Advisory, US Government Resource TA04-196A Source: MS Type: UNKNOWN MS04-023 Source: XF Type: UNKNOWN ie-showhelp-directory-traversal(14105) Source: XF Type: UNKNOWN ie-showhelp-directory-traversal(14105) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1186 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1943 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:3514 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:956 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |