CVE-2007-3406

Microsoft Internet Explorer 6 - Absolute Path Traversal via File URI in Multiple HTML Attributes

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3406. PoCs published by Rajesh Sethumadhavan.

AI-analyzed exploit summary This exploit demonstrates multiple local file access vulnerabilities in Microsoft Internet Explorer 6 via various HTML tags. It allows attackers to verify the presence of local files or potentially access them, depending on the system configuration.

Description

Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) script tag; (2) data attribute of an object tag; (3) value attribute of a param tag; (4) background attribute of a body tag; or (5) the background:url attribute declared in the BODY parameter of a STYLE tag.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Rajesh Sethumadhavan · htmlremotewindows
https://www.exploit-db.com/exploits/29619

This exploit demonstrates multiple local file access vulnerabilities in Microsoft Internet Explorer 6 via various HTML tags. It allows attackers to verify the presence of local files or potentially access them, depending on the system configuration.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer 6 on Windows XP SP2
No auth needed
Prerequisites: Victim must visit a malicious website
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/45435
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22621
Exploit, Vendor Advisory x_refsource_misc
http://www.xdisclose.com/XD100099.txt

Scores

EPSS 0.1089
EPSS Percentile 95.3%

Details

Status published
Products (1)
microsoft/internet_explorer 6
Published Jun 26, 2007
Tracked Since Feb 18, 2026