CVE-2000-0790

Microsoft Internet Explorer 5.5 - Code Injection

Title source: llm
STIX 2.1

Description

The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5097
Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1571
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=3998370D.732A03F1%40nat.bg

Scores

EPSS 0.0139
EPSS Percentile 69.7%

Details

Status published
Products (3)
microsoft/windows_2000
microsoft/windows_98
microsoft/windows_98se
Published Oct 20, 2000
Tracked Since Feb 18, 2026