Back
CVE-2003-1027
Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
Published: Jan 20, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (10)
| Vendor | Product | Version |
|---|---|---|
| microsoft | ie | 6.0 |
| microsoft | internet_explorer | 5.0 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 6.0 |
GitHub Security Advisory GHSA-j6fj-77f5-j227
Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors...
References (30)
- http://marc.info/?l=bugtraq&m=106979479719446&w=2
- http://marc.info/?l=bugtraq&m=107038202225587&w=2
- http://www.kb.cert.org/vuls/id/413886 Third Party Advisory, US Government Resource
- http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2
- http://www.securitytracker.com/id?1006036
- http://www.us-cert.gov/cas/techalerts/TA04-033A.html US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13844
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A527
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A529
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A530
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A531
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A532
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A534
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A629
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
38.05%
Top 2% most likely to be exploited
Threat Score
51.4 / 100
Data Sources
NVD
EPSS
GitHub