CVE-2006-2766
Microsoft Internet Explorer 6.0-6.0 SP2 - Denial of Service via Long mhtml URI in URL File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2766. PoCs published by Mr.Niega.
AI-analyzed exploit summary This exploit leverages a buffer overflow vulnerability in the handling of MHTML URLs in Internet Explorer. The excessively long 'mid:' parameter in the URL triggers the overflow, potentially leading to remote code execution.
Description
Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.
Exploits (1)
This exploit leverages a buffer overflow vulnerability in the handling of MHTML URLs in Internet Explorer. The excessively long 'mid:' parameter in the URL triggers the overflow, potentially leading to remote code execution.