Vulnerability Name: | CVE-2006-2111 (CCN-26281) | ||||||||
Assigned: | 2006-04-27 | ||||||||
Published: | 2006-04-27 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain Information Disclosure Vulnerability." | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-2111 Source: CCN Type: SA19738 Internet Explorer "mhtml:" Redirection Disclosure of Sensitive Information Source: SECUNIA Type: Exploit, Vendor Advisory 19738 Source: CCN Type: SA22477 Internet Explorer 7 "mhtml:" Redirection Information Disclosure Source: SECUNIA Type: Vendor Advisory 22477 Source: MISC Type: Exploit, Vendor Advisory http://secunia.com/Internet_Explorer_Arbitrary_Content_Disclosure_Vulnerability_Test/ Source: CCN Type: SECTRACK ID: 1016005 Microsoft Outlook Express `mhtml:` Redirect URL Processing Lets Remote Users Bypass Security Domains Source: SECTRACK Type: Exploit 1016005 Source: CCN Type: ASA-2007-256 MS07-034 Cumulative Security Update for Outlook Express and Windows Mail (929123) Source: CCN Type: US-CERT VU#783761 Microsoft Windows "MHTML" protocol handler fails to properly handle URL redirections Source: CERT-VN Type: US Government Resource VU#783761 Source: CCN Type: Microsoft Security Bulletin MS07-034 Cumulative Security Update for Outlook Express and Windows Mail (929123) Source: OSVDB Type: UNKNOWN 25073 Source: CCN Type: OSVDB ID: 25073 Microsoft IE mhtml: Redirection Domain Restriction Bypass Source: BUGTRAQ Type: UNKNOWN 20061026 IE7 is a Source of Problem - Secunia IE7 Release Incident of October 2006 Source: BUGTRAQ Type: UNKNOWN 20061025 IE7 status: 8 days after release, 3 unfixed issues Source: HP Type: UNKNOWN SSRT071438 Source: BID Type: UNKNOWN 17717 Source: CCN Type: BID-17717 Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability Source: CERT Type: US Government Resource TA07-163A Source: VUPEN Type: Vendor Advisory ADV-2006-1558 Source: VUPEN Type: Vendor Advisory ADV-2007-2154 Source: MS Type: UNKNOWN MS07-034 Source: XF Type: UNKNOWN ie-mhtml-information-disclosure(26281) Source: XF Type: UNKNOWN ie-mhtml-information-disclosure(26281) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1605 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |