>> Microsoft Windows 2000 Web View Vulnerability (MS05-024)
Title : Microsoft Windows 2000 Web View Vulnerability (MS05-024) VUPEN ID : VUPEN/ADV-2005-0509 CVE ID : CVE-2005-1191 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-05-10
Technical Description
A new vulnerability was identified in Microsoft Windows, which may be exploited by attackers to execute arbitrary commands. This flaw is due to an input validation error in the way that Web View (webvw.dll) within Windows Explorer handles certain HTML characters in preview fields, which may be exploited to compromise a vulnerable system by persuading a user to preview a specially crafted file.