CVE-2006-2900: Infoleak
Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2900?
CVE-2006-2900 is rated as a moderate vulnerability due to its dependency on user interaction.
How can I mitigate the effects of CVE-2006-2900?
To mitigate CVE-2006-2900, users should avoid entering sensitive information into untrusted websites and consider using modern browsers that are not affected.
What versions of Internet Explorer are affected by CVE-2006-2900?
CVE-2006-2900 affects Internet Explorer 6 on multiple platforms including Windows 2000, Windows XP, and Windows Server 2003.
Can I still use Internet Explorer 6 safely in light of CVE-2006-2900?
Using Internet Explorer 6 is not recommended due to its vulnerabilities, including CVE-2006-2900, and it's advisable to upgrade to a more secure browser.
What type of attack does CVE-2006-2900 facilitate?
CVE-2006-2900 allows user-assisted remote attackers to read arbitrary files by exploiting keyboard event handling in Internet Explorer.