PT-2007-4808 · Microsoft · Internet Explorer
Published
2007-07-03
·
Updated
2024-08-07
·
CVE-2007-3550
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 6.0 through 7.0
Description
The issue allows remote attackers to fill Zones with arbitrary domains using certain metacharacters, such as wildcards, via JavaScript. This results in a denial of service, including website suppression and resource consumption. However, it is noted that a third party has disputed this issue, stating that the zone settings cannot be manipulated.
Recommendations
For Microsoft Internet Explorer versions 6.0 through 7.0, consider restricting the use of JavaScript to minimize the risk of exploitation, as a temporary workaround, until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer