CVE-2006-3472

Microsoft Internet Explorer 6.0-6.0 SP1 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-3472. PoCs published by jsz.

AI-analyzed exploit summary This exploit demonstrates a denial-of-service vulnerability in Microsoft Internet Explorer by using an HTML 'href' tag with an excessively large title attribute, causing the application to stop responding.

Description

Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via an HTML page with an A tag containing a long title attribute. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by jsz · htmldoswindows
https://www.exploit-db.com/exploits/28164

This exploit demonstrates a denial-of-service vulnerability in Microsoft Internet Explorer by using an HTML 'href' tag with an excessively large title attribute, causing the application to stop responding.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer (versions affected by CVE-2006-3472)
No auth needed
Prerequisites: Victim must open the malicious HTML file in a vulnerable version of Internet Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18820
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/30822

Scores

EPSS 0.1057
EPSS Percentile 95.2%

Details

Status published
Products (2)
microsoft/ie 6.0 sp1
microsoft/internet_explorer 6.0
Published Jul 10, 2006
Tracked Since Feb 18, 2026