Download.Ject JavaScript server side execution (DownloadjectJavascriptExecution)

Vuln ID: 16544
Risk Level: High risk vulnerability  High DownloadjectJavascriptExecution
Platforms: Microsoft Windows 98, Microsoft Windows 98SE, Microsoft Windows Me, Microsoft NetMeeting, Microsoft Windows XP, Microsoft Windows 2000: SP2, Microsoft Windows 2000: SP3, Microsoft Windows XP: SP1, Microsoft Windows 2000: SP4, Microsoft Windows NT: 4.0 SP6a Workstation, Microsoft Windows NT: 4.0 SP6a Server, Microsoft Windows XP: 2003 x64, Microsoft Windows 2003 Server: x64, Microsoft Windows 2003 Server, Microsoft Windows NT: 4.0 SP6 Terminal Server, Microsoft Internet Information Server: 5.0, Microsoft Windows XP: SP1 x64
Description:

Download.Ject, also known as JS.Scob.Trojan, Scob, and JS.Toofeer, is a Trojan that executes a JavaScript file from a remote server. The Trojan affects Microsoft Internet Information Services (IIS) version 5.0 and exploits a vulnerability in Microsoft Security Bulletin MS04-011. An attacker can append an executable file to a Web page that exists on a server running IIS. When a victim requests a Web page containing the executable from the server, the Trojan is downloaded and executed on the victim's system.

Remedy:

Apply the appropriate patches for your system, as listed in Microsoft Security Bulletin MS04-011. See References.

False Positives:
False Negatives:
Required Permission:
Additional Information:

References:

Microsoft Security Bulletin MS04-011
Security Update for Microsoft Windows (835732)
http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx

Microsoft.com Web site
What You Should Know About Download.Ject
http://www.microsoft.com/security/incident/download_ject.mspx

IBM Internet Security Systems X-Force Database
Microsoft Internet Explorer Location: header bypass restrictions
http://xforce.iss.net/xforce/xfdb/16348

IBM Internet Security Systems X-Force Database
Microsoft Internet Explorer ADODB.Stream object code execution
http://xforce.iss.net/xforce/xfdb/16394

IBM Internet Security Systems X-Force Database
Microsoft Internet Explorer Shell.Application
http://xforce.iss.net/xforce/xfdb/16648

ISS X-Force
Download.Ject JavaScript server side execution
http://www.iss.net/security_center/static/16544.php

CVE CVE-2004-0549
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0549


X-Force Logo
Know Your Risks
Mitre.org CVE Logo
Common Vulnerabilties & Exposures