PT-2005-1217 · Microsoft · Internet Explorer+1
Rafel Ivgi
+1
·
Published
2005-01-14
·
Updated
2016-10-18
·
CVE-2005-0110
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer version 6 on Windows XP SP2
Description
The issue allows remote attackers to bypass the file download warning dialog, potentially tricking users into executing arbitrary code. This can be achieved through a web page containing a body element with an onclick tag, utilizing the createElement function.
Recommendations
For Internet Explorer 6 on Windows XP SP2, consider disabling the onclick functionality in the body element as a temporary workaround until a patch is available. Restrict access to web pages that utilize the createElement function to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer
Windows Xp