Back

CVE-2004-1155

Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (18)

Vendor Product Version
microsoft ie 5.0.1
microsoft ie 5.0.1
microsoft ie 5.0.1
microsoft ie 5.0.1
microsoft ie 5.2.3
microsoft ie 6.0
microsoft ie 6.0
microsoft ie 7.0
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-7ph8-m5fp-w25v

Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 12.58%

Top 4% most likely to be exploited

Threat Score 33.8 / 100

Data Sources

NVD EPSS GitHub