PT-2006-2207 · Microsoft · Internet Explorer

Published

2006-04-11

·

Updated

2021-07-23

·

CVE-2006-1191

CVSS v2.0

4.0

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 5.01 through 6
Description The issue allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site. This is due to the way Internet Explorer handles navigation methods, which can lead to information disclosure if a user visits a malicious Web site or views a specially crafted e-mail message. An attacker who successfully exploits this could read cookies or other data from another Internet Explorer domain, but user interaction is required.
Recommendations For Microsoft Internet Explorer versions 5.01 through 6, consider restricting access to sensitive information and avoiding the use of potentially vulnerable navigation methods until a fix is available. As a temporary workaround, users should be cautious when navigating to different sites and avoid interacting with suspicious Web pages or e-mail messages.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1191

Affected Products

Internet Explorer