CVE-2004-2090
medium · 5Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.
5
CVSS
16.0%
EPSS (exploit prob.)
97th
EPSS percentile
2004-02-07
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | ie | 6.0 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 6.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016881.html
- http://secunia.com/advisories/10820
- http://www.securityfocus.com/bid/9611
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15078
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016881.html
- http://secunia.com/advisories/10820
- http://www.securityfocus.com/bid/9611
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15078
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-2090