Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-011
http://www.iss.net/security_center/static/1276.php
http://support.microsoft.com/support/kb/articles/q191/2/00.asp