PT-2005-1217 · Microsoft · Internet Explorer+1
Rafel Ivgi
+1
·
Publicado
2005-01-14
·
Atualizado
2016-10-18
·
CVE-2005-0110
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer version 6 on Windows XP SP2
Description
The issue allows remote attackers to bypass the file download warning dialog, potentially tricking users into executing arbitrary code. This can be achieved through a web page containing a body element with an onclick tag, utilizing the createElement function.
Recommendations
For Internet Explorer 6 on Windows XP SP2, consider disabling the onclick functionality in the body element as a temporary workaround until a patch is available. Restrict access to web pages that utilize the createElement function to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer
Windows Xp