CVE-2005-1191
The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.
- Affected products
- Windows 2000, Windows Explorer
- Microsoft Windows 2000
- All versions
- Microsoft Windows 98
- All versions
- Microsoft Windows 98se
- All versions
- Microsoft Windows Me
- All versions
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 17.1% (97th percentile)
- NVD status
- Modified
- Published
- 2005-04-19
CVE-2005-1191 at NVD
1 known exploit for CVE-2005-1191
Proof-of-concept code and exploit modules indexed by Sploitus