|
|
View Definition
| Definition Id: oval:org.mitre.oval:def:462 |
Date: 2007-01-11 |
| Title: |
FTP Server Command Injection Vulnerability |
| Description: |
CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command. |
| Version: |
2 |
Class: |
vulnerability |
| Status: |
ACCEPTED |
Reference(s): |
CVE-2004-1166
|
| Family: |
windows |
| Platform(s): |
Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 |
Product(s): |
Microsoft Internet Explorer |
| Definition Synopsis: |
- Server 2003-Gold
- OR XP,SP1 (64-bit) and Server 2003, SP1
- OR IE 6 on Windows XP,SP2
- OR IE 6 on Windows 2000 or XP,SP1 (32-bit)
- OR IE 5.01,SP4 on Win2k,SP4
|
|
|