CVE-2006-1191

Microsoft Internet Explorer <6 - Info Disclosure

Title source: llm

Description

Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.

Exploits (1)

exploitdb WORKING POC
htmldoswindows
https://www.exploit-db.com/exploits/1838

Scores

EPSS 0.5028
EPSS Percentile 97.8%

Details

Status published
Products (4)
microsoft/internet_explorer 5.01
microsoft/internet_explorer 5.1
microsoft/internet_explorer 5.5
microsoft/internet_explorer 6.0
Published Apr 11, 2006
Tracked Since Feb 18, 2026