CVE-2013-3166

Microsoft Internet Explorer 6-10 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via vectors involving incorrect auto-selection of the Shift JIS encoding, leading to cross-domain scrolling events, aka "Shift JIS Character Encoding Vulnerability," a different vulnerability than CVE-2013-0015.

Exploits (1)

exploitdb WORKING POC
rubyremotewindows
https://www.exploit-db.com/exploits/28187

Scores

EPSS 0.1800
EPSS Percentile 95.1%

Classification

CWE
CWE-79
Status draft

Affected Products (5)

microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer

Timeline

Published Jul 10, 2013
Tracked Since Feb 18, 2026