PT-2006-2207 · Microsoft · Internet Explorer
Published
2006-04-11
·
Updated
2021-07-23
·
CVE-2006-1191
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 5.01 through 6
Description
The issue allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site. This is due to the way Internet Explorer handles navigation methods, which can lead to information disclosure if a user visits a malicious Web site or views a specially crafted e-mail message. An attacker who successfully exploits this could read cookies or other data from another Internet Explorer domain, but user interaction is required.
Recommendations
For Microsoft Internet Explorer versions 5.01 through 6, consider restricting access to sensitive information and avoiding the use of potentially vulnerable navigation methods until a fix is available. As a temporary workaround, users should be cautious when navigating to different sites and avoid interacting with suspicious Web pages or e-mail messages.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer