Back

CVE-2004-2383

Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categorize this as a vulnerability, but it can be used in a spoofing scenario; the discloser provides alternate scenarios. Spoofing scenarios are currently included in CVE.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
microsoft ie 6.0
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-xm8c-6w35-cmxv

Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame...

Risk Scores

CVSS Score 5.1 / 10
EPSS Score 19.97%

Top 3% most likely to be exploited

Threat Score 26.4 / 100

Data Sources

NVD EPSS GitHub