vendor:
Windows
by:
SecurityFocus
7,5
CVSS
HIGH
Script Injection
94
CWE
Product Name: Windows
Affected Version From: Windows 98/98SE/ME
Affected Version To: Windows 2000
Patch Exists: Yes
Related CWE: CVE-2002-0649
CPE: o:microsoft:windows
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Microsoft Windows Explorer Script Injection Vulnerability
Microsoft Windows Explorer is prone to a script injection vulnerability. This occurs when the Windows Explorer preview pane (Web View) is enabled on Windows 2000 computers. Windows 98/98SE/ME are also affected by this issue. If a file with malicious attributes is selected using Explorer, script code contained in the attribute fields may be executed with the privilege level of the user that invoked Explorer. This could be exploited to gain unauthorized access to the vulnerable computer in the context of the currently logged in user.
Mitigation:
Disable the Windows Explorer preview pane (Web View) on Windows 2000 computers.