Back
CVE-2004-2383
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categorize this as a vulnerability, but it can be used in a spoofing scenario; the discloser provides alternate scenarios. Spoofing scenarios are currently included in CVE.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| microsoft | ie | 6.0 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 6.0 |
GitHub Security Advisory GHSA-xm8c-6w35-cmxv
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame...
References (6)
- http://www.idefense.com/application/poi/display?id=77&type=vulnerabilities&flashstatus=false
- http://www.securityfocus.com/bid/9761 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15337
- http://www.idefense.com/application/poi/display?id=77&type=vulnerabilities&flashstatus=false
- http://www.securityfocus.com/bid/9761 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15337
Risk Scores
CVSS Score
5.1 / 10
EPSS Score
19.97%
Top 3% most likely to be exploited
Threat Score
26.4 / 100
Data Sources
NVD
EPSS
GitHub