CVE-2005-1989

Internet Explorer <6.0 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1989.

AI-analyzed exploit summary This is a functional exploit for CVE-2005-1989, targeting a vulnerability in Internet Explorer's COM object instantiation (MS05-038). It uses a heap spray technique to execute a bind shell on port 28876 via the vulnerable 'blnmgr.dll' CLSID.

Description

Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".

Exploits (1)

exploitdb WORKING POC
htmlremotewindows
https://www.exploit-db.com/exploits/1144

This is a functional exploit for CVE-2005-1989, targeting a vulnerability in Internet Explorer's COM object instantiation (MS05-038). It uses a heap spray technique to execute a bind shell on port 28876 via the vulnerable 'blnmgr.dll' CLSID.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Internet Explorer 6 on Windows XP SP2
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Internet Explorer 6 with vulnerable COM object accessible
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A790
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A888
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1319
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16373/
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100081
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14512
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100082
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A697
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1353

Scores

EPSS 0.6278
EPSS Percentile 98.4%

Details

Status published
Products (3)
microsoft/ie 6 windows_server_2003_sp1
microsoft/internet_explorer 5.01
microsoft/internet_explorer 5.5
Published Aug 10, 2005
Tracked Since Feb 18, 2026