Vulnerability Name: | CVE-2005-3312 (CCN-22379) | ||||||||
Assigned: | 2005-09-22 | ||||||||
Published: | 2005-09-22 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on the link, even though the web server response and file extension indicate that it should be treated as a different file type. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:POC/RL:U/RC:UC)
2.1 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:POC/RL:U/RC:UC)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Sep 22 2005 - 13:30:38 CDT Microsoft Internet Explorer 6.0 embedded content cross site scripting Source: MITRE Type: CNA CVE-2005-3312 Source: BUGTRAQ Type: UNKNOWN 20051022 phpBB 2.0.17 (and other BB systems as well) Cookie disclosure Source: SREASON Type: UNKNOWN 18 Source: MISC Type: Exploit http://www.computec.ch/download.php?view.683 Source: CCN Type: Internet Explorer Web site Internet Explorer Home Source: CCN Type: OSVDB ID: 20248 Microsoft IE Embedded Content Processing XSS Source: CCN Type: OSVDB ID: 31333 Microsoft IE Image File Embedded Content XSS Source: MISC Type: Exploit, Vendor Advisory http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=1746 Source: CCN Type: SecuriTeam Windows NT Focus 10 Oct. 2005 Microsoft Internet Explorer 6.0 Embedded Content Cross Site Scripting (GIF) Source: MISC Type: Vendor Advisory http://www.securiteam.com/windowsntfocus/6F00B00EBY.html Source: XF Type: UNKNOWN ie-web-content-controlled-xss(22379) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |