Description
Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement function.
References (1)
Core 1
Core References
Mailing List mailing-list
x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=110569119106172&w=2
Scores
EPSS
0.0683
EPSS Percentile
93.4%
Details
Status
published
Products (1)
microsoft/ie
6.0 sp2
Published
Jan 14, 2005
Tracked Since
Feb 18, 2026