peter bassill · operator
$ cve CVE-2004-2090 JSON

CVE-2004-2090 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 16% (pctl 97)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS16.02% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2004-02-07
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftie
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD