Back

CVE-2004-0843

Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."

Published: Nov 3, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft ie 6
microsoft internet_explorer 5.5

GitHub Security Advisory GHSA-28rc-mq4v-8p47

Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 33.79%

Top 2% most likely to be exploited

Threat Score 30.1 / 100

Data Sources

NVD EPSS GitHub