CVE-2007-5158

Microsoft Internet Explorer 6.0 - XSS

Title source: llm

Description

The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a file upload field, a related issue to CVE-2007-3511.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ronald van den Heetkamp · htmlremotewindows
https://www.exploit-db.com/exploits/30622

Scores

EPSS 0.2059
EPSS Percentile 95.6%

Details

Status published
Products (1)
microsoft/internet_explorer 6.0
Published Oct 01, 2007
Tracked Since Feb 18, 2026