CVE-2004-2219

low Microsoft
CVSS v3 Base Score
2.6
AV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS Score
15.1%
Exploitation probability in 30 days
Top 5% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Confidentiality
None
Integrity
P
Availability
None
Published: December 31, 2004 (7804 days ago)
Last Modified: April 16, 2026
Vendor: Microsoft
Source: NVD

Description

Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.

CWE

NVD-CWE-Other

Affected Products

microsoft iemicrosoft internet explorer

References