| Download.Ject JavaScript server side execution (DownloadjectJavascriptExecution) |
|---|
| Vuln ID: | 16544 | |
|---|---|---|
| Risk Level: | High |
DownloadjectJavascriptExecution |
| Platforms: | Microsoft Windows 98, Microsoft Windows 98SE, Microsoft Windows Me, Microsoft NetMeeting, Microsoft Windows XP, Microsoft Windows 2000: SP2, Microsoft Windows 2000: SP3, Microsoft Windows XP: SP1, Microsoft Windows 2000: SP4, Microsoft Windows NT: 4.0 SP6a Workstation, Microsoft Windows NT: 4.0 SP6a Server, Microsoft Windows XP: 2003 x64, Microsoft Windows 2003 Server: x64, Microsoft Windows 2003 Server, Microsoft Windows NT: 4.0 SP6 Terminal Server, Microsoft Internet Information Server: 5.0, Microsoft Windows XP: SP1 x64 | |
| Description: | Download.Ject, also known as JS.Scob.Trojan, Scob, and JS.Toofeer, is a Trojan that executes a JavaScript file from a remote server. The Trojan affects Microsoft Internet Information Services (IIS) version 5.0 and exploits a vulnerability in Microsoft Security Bulletin MS04-011. An attacker can append an executable file to a Web page that exists on a server running IIS. When a victim requests a Web page containing the executable from the server, the Trojan is downloaded and executed on the victim's system. |
|
| Remedy: | Apply the appropriate patches for your system, as listed in Microsoft Security Bulletin MS04-011. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | ||
| Additional Information: | ||
| References: | Microsoft Security Bulletin MS04-011 Microsoft.com Web site IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database ISS X-Force CVE CVE-2004-0549 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |