PT-2006-6288 · Microsoft · Internet Explorer
Published
2006-12-12
·
Updated
2018-10-17
·
CVE-2006-5577
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Internet Explorer versions 6 and earlier
Description:
The issue allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder. An information disclosure vulnerability exists in certain scenarios where the path to the cached content in the TIF folder could be disclosed. An attacker could exploit the issue by constructing a specially crafted Web page that could allow for information disclosure if a user viewed the Web page. This would enable the attacker to retrieve files from the Temporary Internet Files (TIF) folder on a user's system, but user interaction is required to exploit the issue.
Recommendations:
For Microsoft Internet Explorer versions 6 and earlier, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer