CVE-2004-0839

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".

Date published : 2004-09-14

http://www.securityfocus.com/bid/10973

http://marc.info/?l=bugtraq&m=109303291513335&w=2