New Search

IE6.0SP2 Security Zone Restriction Bypass Vulnerability

oval:org.mitre.oval:def:3196

Internet Explorer 5.01 5.5 and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded which are decoded twice to generate a malicious hostname aka the "URL Decoding Zone Spoofing Vulnerability."

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows XP
Class:
vulnerability
Reference(s):
  • CVE-2005-0054
Product(s):
  • Microsoft Internet Explorer