Lucene search

K
cveMicrosoftCVE-2006-1191
HistoryApr 11, 2006 - 11:02 p.m.

CVE-2006-1191

2006-04-1123:02:00
microsoft
web.nvd.nist.gov
44
4
microsoft
internet explorer
cve-2006-1191
cross-domain
info disclosure
scripting
vulnerability

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.202

Percentile

96.4%

Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.

Affected configurations

Nvd
Node
microsoftinternet_explorerMatch5.01
OR
microsoftinternet_explorerMatch5.1
OR
microsoftinternet_explorerMatch5.5
OR
microsoftinternet_explorerMatch6.0
VendorProductVersionCPE
microsoftinternet_explorer5.01cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
microsoftinternet_explorer5.1cpe:2.3:a:microsoft:internet_explorer:5.1:*:*:*:*:*:*:*
microsoftinternet_explorer5.5cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
microsoftinternet_explorer6.0cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

Social References

More

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.202

Percentile

96.4%