Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-1191
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-1191

Description:
The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/20380

OVAL
  http://oval.mitre.org/oval/definitions/data/oval3585.html

MS
  http://www.microsoft.com/technet/security/bulletin/ms05-024.mspx

MISC
  http://security.greymagic.com/security/advisories/gm015-ie

BUGTRAQ
  http://www.securityfocus.com/archive/1/396224

BID
  13248


Return to the previous page.