EIP-2026-118811
PRE-CVEMicrosoft Internet Explorer 5 - NavigateAndFind() Cross-Zone Policy (MS04-004)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118811. PoCs published by Andreas Sandblad.
AI-analyzed exploit summary This exploit leverages a vulnerability in Microsoft Internet Explorer where JavaScript URIs are not properly removed from the browser history list. By injecting a JavaScript URI into the history, an attacker can execute arbitrary code in the Local Machine security zone when the user navigates back.
Description
Microsoft Internet Explorer 5 - NavigateAndFind() Cross-Zone Policy (MS04-004)
Exploits (1)
This exploit leverages a vulnerability in Microsoft Internet Explorer where JavaScript URIs are not properly removed from the browser history list. By injecting a JavaScript URI into the history, an attacker can execute arbitrary code in the Local Machine security zone when the user navigates back.