Back

CVE-2004-1166

CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

Published: Dec 31, 2004 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (3)

Vendor Product Version
microsoft ie 6.0
microsoft ie 6.0
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-c8f8-rjv5-g482

CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 39.17%

Top 2% most likely to be exploited

Threat Score 41.7 / 100

Data Sources

NVD EPSS GitHub