CVE-2015-6176

Microsoft Edge - XSS

Title source: rule

Description

Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability."

Exploits (1)

exploitdb WORKING POC
by nu11secur1ty · textremotewindows
https://www.exploit-db.com/exploits/52372

Scores

EPSS 0.0430
EPSS Percentile 88.9%

Details

CWE
CWE-79
Status published
Products (1)
microsoft/edge
Published Dec 09, 2015
Tracked Since Feb 18, 2026