CVE-2004-2090 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 16% (pctl 97)
Patch early
A public exploit exists.
Description
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 16.02% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-02-07 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | ie |
| microsoft | internet explorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 5.0.1 - LoadPicture File Enumeration | 2004-02-07 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016881.html
- http://secunia.com/advisories/10820
- http://www.securityfocus.com/bid/9611
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15078
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016881.html
- http://secunia.com/advisories/10820
- http://www.securityfocus.com/bid/9611
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15078
→ the Explorer · watch your stack · NVD