CVE-2004-1319
Title: Microsoft DHTML Edit Control cross-domain script injection
XSS
Proof Of Concept
No public PoC currently indexed for CVE-2004-1319.
CWE Category
NVD-CWE-noinfo
Published Date
Dec 15, 2004
Modified Date
Apr 03, 2025
Exploit Status
Not Found
Score
5.0
CVSS v2.0
Exploit Probability (EPSS)
31.30%
Vulnerability Summary
CVE-2004-1319: The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.
Impacted Vendors
Reference Links
http://archives.neohapsis.com/archives/bugtraq/2004-12/0167.html
http://freehost07.websamba.com/greyhats/abusiveparent-discussion.htm
http://secunia.com/advisories/13482/
http://www.kb.cert.org/vuls/id/356600
http://www.securityfocus.com/bid/11950
http://www.us-cert.gov/cas/techalerts/TA05-039A.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-013
https://exchange.xforce.ibmcloud.com/vulnerabilities/18504
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1114
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1701
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3464
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3851
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4758
http://archives.neohapsis.com/archives/bugtraq/2004-12/0167.html
http://freehost07.websamba.com/greyhats/abusiveparent-discussion.htm
http://secunia.com/advisories/13482/
http://www.kb.cert.org/vuls/id/356600
http://www.securityfocus.com/bid/11950
http://www.us-cert.gov/cas/techalerts/TA05-039A.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-013
https://exchange.xforce.ibmcloud.com/vulnerabilities/18504
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1114
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1701
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3464
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3851
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4758
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
5.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:N/C:N/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2004-1319 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:N/C:N/I:P/A:N
Affected Stack
No specific products linked.