PT-2006-5353 · Microsoft · Internet Explorer 6

Maddin

·

Published

2006-09-06

·

Updated

2024-02-14

·

CVE-2006-4560

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Internet Explorer 6 version
Description The issue allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server. This can be achieved by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control. The attack can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
Recommendations For Internet Explorer 6, consider disabling JavaScript execution until a patch is available. Restrict access to intranet web servers to minimize the risk of exploitation. Avoid accessing Internet web servers with domain names that can be controlled by potential attackers.

Exploit

Fix

Related Identifiers

CVE-2006-4560

Affected Products

Internet Explorer 6