IE6.0SP1 Security Zone Restriction Bypass Vulnerability
Internet Explorer 5.01 5.5 and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded which are decoded twice to generate a malicious hostname aka the "URL Decoding Zone Spoofing Vulnerability."
- Microsoft Windows 2000
- Microsoft Windows XP
- Microsoft Internet Explorer