First published: Mon May 01 2006(Updated: )
A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain Information Disclosure Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Outlook Express | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2111 is classified as a moderate severity vulnerability.
CVE-2006-2111 allows remote attackers to bypass domain restrictions through the mhtml: URI handler, leading to potential information disclosure.
The impacts of CVE-2006-2111 include unauthorized access to sensitive information through redirection attacks.
To mitigate CVE-2006-2111, users should avoid using Microsoft Outlook Express 6 or ensure that security patches are applied.
While CVE-2006-2111 was reported a while ago, it may still pose a risk for users of unsupported software.