CVE-2015-6176
Microsoft Edge - Cross-Site Scripting Filter Bypass via HTML Attribute Mishandling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-6176. PoCs published by nu11secur1ty.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in Microsoft Edge on Windows 10 Version 1511. It sets up a web server to serve a malicious HTML page that collects sensitive browser data (cookies, URL, referrer, etc.) and exfiltrates it to an attacker-controlled collector server.
Description
Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability."
Exploits (1)
This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in Microsoft Edge on Windows 10 Version 1511. It sets up a web server to serve a malicious HTML page that collects sensitive browser data (cookies, URL, referrer, etc.) and exfiltrates it to an attacker-controlled collector server.