| Definition Id: oval:org.mitre.oval:def:3006 |
Version: 5
Last Modified: 2010-01-13
|
| Title: |
IE5.01,SP3 Drag-and-Drop Vulnerability |
| Description: |
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability." |
| Family: |
windows |
Class: |
vulnerability |
| Status: |
ACCEPTED |
Reference(s): |
CVE-2005-0053
|
| Platform(s): |
Microsoft Windows 2000 |
Product(s): |
Microsoft Internet Explorer |
| Definition Synopsis: |
- Software section
- AND Configuration section
- Check for Drag&Drop enabled and the patch kb834707(wildcard*) missing
- AND ActiveX controls and active scripting are enabled
- current user settings are being used and ActiveX controls and active scripting are enabled
- OR local machine settings are being used and ActiveX controls and active scripting are enabled
|