Vulnerability CVE-2005-3312


Published: 2005-10-26   Modified: 2012-02-12

Description:
The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on the link, even though the web server response and file extension indicate that it should be treated as a different file type.

See advisories in our WLB2 database:
Topic
Author
Date
Low
Microsoft Internet Explorer 6.0 embedded content cross site scripting
Marc Ruef
24.09.2005

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Microsoft -> IE 

 References:
http://www.securiteam.com/windowsntfocus/6F00B00EBY.html
http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=1746
http://www.computec.ch/download.php?view.683
http://marc.theaimsgroup.com/?l=bugtraq&m=113017003617987&w=2
http://securityreason.com/securityalert/18

Copyright 2024, cxsecurity.com

 

Back to Top