vendor:
Internet Explorer
by:
Aviv Raff
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 6
Affected Version To: Internet Explorer 6
Patch Exists: YES
Related CWE: CVE-2006-3869
CPE: a:microsoft:internet_explorer:6.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2006
Internet Explorer 6 DOM-Hanoi Fuzzer Script Vulnerability
The vulnerability exists due to a boundary error when handling certain combinations of elements in a DOM tree. An attacker can exploit this vulnerability by creating a malicious web page containing a specially crafted combination of elements and then convincing a user to view the page. This can result in a buffer overflow, allowing the attacker to execute arbitrary code on the user's system with the privileges of the user.
Mitigation:
Microsoft has released a patch to address this vulnerability.