PT-2006-5353 · Microsoft · Internet Explorer 6
Maddin
·
Published
2006-09-06
·
Updated
2024-02-14
·
CVE-2006-4560
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Explorer 6 version
Description
The issue allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server. This can be achieved by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control. The attack can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
Recommendations
For Internet Explorer 6, consider disabling JavaScript execution until a patch is available. Restrict access to intranet web servers to minimize the risk of exploitation. Avoid accessing Internet web servers with domain names that can be controlled by potential attackers.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer 6