EIP-2026-118842
PRE-CVEMicrosoft Internet Explorer 6 - window.open Media Bar Cross-Zone Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118842. PoCs published by Jelmer.
AI-analyzed exploit summary This exploit leverages a cross-zone scripting vulnerability in Microsoft Internet Explorer 6 and above, allowing execution of arbitrary script code in the context of the My Computer Zone via the '_media' property of the 'window.open' method. It demonstrates file creation and cross-site scripting (XSS) by injecting malicious JavaScript.
Description
Microsoft Internet Explorer 6 - window.open Media Bar Cross-Zone Scripting
Exploits (1)
This exploit leverages a cross-zone scripting vulnerability in Microsoft Internet Explorer 6 and above, allowing execution of arbitrary script code in the context of the My Computer Zone via the '_media' property of the 'window.open' method. It demonstrates file creation and cross-site scripting (XSS) by injecting malicious JavaScript.