CVE-1999-0489

Windows NT - Unauthenticated Arbitrary File Upload via MSHTML.DLL File Upload Control

Title source: llm
STIX 2.1

Description

MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.

References (1)

Core 1
Core References

Scores

EPSS 0.1245
EPSS Percentile 95.8%

Details

Status published
Products (1)
microsoft/windows_nt 4.0
Published May 17, 1999
Tracked Since Feb 18, 2026