CVE-2006-7031

MEDIUM

Microsoft Internet Explorer < 6.0.2900 - Denial of Service via CSS Position Attribute

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-7031. PoCs published by seven.

AI-analyzed exploit summary This exploit demonstrates a DoS vulnerability in Internet Explorer <= 6.0.2900 SP2 by crashing the browser when a user hovers over a specially crafted table with the 'position' CSS attribute set. The crash occurs due to an unhandled exception in MSHTML.DLL.

Description

Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a table element with a CSS attribute that sets the position, which triggers an "unhandled exception" in mshtml.dll.

Exploits (1)

exploitdb WORKING POC VERIFIED
by seven · htmldoswindows
https://www.exploit-db.com/exploits/1775

This exploit demonstrates a DoS vulnerability in Internet Explorer <= 6.0.2900 SP2 by crashing the browser when a user hovers over a specially crafted table with the 'position' CSS attribute set. The crash occurs due to an unhandled exception in MSHTML.DLL.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Internet Explorer <= 6.0.2900 SP2
No auth needed
Prerequisites: Victim must use Internet Explorer <= 6.0.2900 SP2 · Victim must hover over the malicious table
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1775
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17932

Scores

CVSS v3 6.5
EPSS 0.1745
EPSS Percentile 96.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

Status published
Products (1)
microsoft/internet_explorer < 6.0.2900
Published Feb 23, 2007
Tracked Since Feb 18, 2026