CVE-2006-3280

Microsoft Internet Explorer 6.0 - Info Disclosure

Title source: llm

Description

Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, aka "Redirect Cross-Domain Information Disclosure Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Plebo Aesdi Nael · htmlremotewindows
https://www.exploit-db.com/exploits/28118

References (20)

Scores

EPSS 0.6208
EPSS Percentile 98.4%

Details

Status published
Products (1)
microsoft/internet_explorer 6.0
Published Jun 28, 2006
Tracked Since Feb 18, 2026