VDB
CVE-2005-1191
CVE-2005-1191
PUBLISHED
CVSS 5 MEDIUM
The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.
EPSS 25.57% · 96.3th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
25.57%
96.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_98se | |
| microsoft | windows_2000 | |
| microsoft | windows_98 | |
| microsoft | windows_me | |
| n/a | n/a | n/a |
Timeline
- Apr 19, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Aug 9, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- 20050419 File Selection May Lead to Command Execution (GM#015-IE) mailing-list
- 13248 vdb
- ADV-2005-0509 vdb
- windows-web-view-command-execution(20380) vdb
- http://security.greymagic.com/security/advisories/gm015-ie url
- MS05-024 vendor-advisory
- oval:org.mitre.oval:def:3585 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2005-1191 advisory