Back

CVE-2004-0841

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."

Published: Dec 23, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (16)

Vendor Product Version
avaya ip600_media_servers *
microsoft ie 6.0
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0
avaya definity_one_media_server *
avaya s3400 *
avaya s8100 *
avaya modular_messaging_message_storage_server 1.1
avaya modular_messaging_message_storage_server 2.0

GitHub Security Advisory GHSA-fgjq-p2q2-66cx

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 48.73%

Top 1% most likely to be exploited

Threat Score 34.6 / 100

Data Sources

NVD EPSS GitHub