EIP-2026-118842

PRE-CVE

Microsoft Internet Explorer 6 - window.open Media Bar Cross-Zone Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118842. PoCs published by Jelmer.

AI-analyzed exploit summary This exploit leverages a cross-zone scripting vulnerability in Microsoft Internet Explorer 6 and above, allowing execution of arbitrary script code in the context of the My Computer Zone via the '_media' property of the 'window.open' method. It demonstrates file creation and cross-site scripting (XSS) by injecting malicious JavaScript.

Description

Microsoft Internet Explorer 6 - window.open Media Bar Cross-Zone Scripting

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jelmer · textremotewindows
https://www.exploit-db.com/exploits/23768

This exploit leverages a cross-zone scripting vulnerability in Microsoft Internet Explorer 6 and above, allowing execution of arbitrary script code in the context of the My Computer Zone via the '_media' property of the 'window.open' method. It demonstrates file creation and cross-site scripting (XSS) by injecting malicious JavaScript.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer 6 and above
No auth needed
Prerequisites: Victim must be using Internet Explorer 6 or above · Victim must visit a malicious webpage or have malicious script injected into a trusted page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026