CVE-2006-4560
published 2006-09-06CVE-2006-4560: Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
18.26%
96.9th percentile
Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rxph-92gh-ccv4: Microsoft Internet Explorer 6 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduc
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2007-5277 [HIGH] GHSA-rxph-92gh-ccv4: Microsoft Internet Explorer 6 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduc
Microsoft Internet Explorer 6 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been established for a session on port 80, a different issue than CVE-2006-4560.
GHSA
GHSA-f53c-gmxc-3ww8: Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrar
ghsa_unreviewed·2022-05-01
CVE-2006-4560 [HIGH] GHSA-f53c-gmxc-3ww8: Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrar
Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
No detection rules found.
No public exploits indexed.
http://polyboy.net/xss/dnsslurp.htmlhttp://shampoo.antville.org/stories/1451301/http://www.osvdb.org/31329http://www.securityfocus.com/archive/1/443209/100/200/threadedhttp://polyboy.net/xss/dnsslurp.htmlhttp://shampoo.antville.org/stories/1451301/http://www.osvdb.org/31329http://www.securityfocus.com/archive/1/443209/100/200/threaded
2006-09-06
Published