First published: Tue Aug 08 2006(Updated: )
Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layout positioning combinations in an HTML file.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3450 has a high severity rating due to its ability to allow remote code execution.
To fix CVE-2006-3450, update Microsoft Internet Explorer to the latest version available from Microsoft.
CVE-2006-3450 affects Microsoft Internet Explorer version 6.0 and specifically 6.0 SP1.
Yes, CVE-2006-3450 can be exploited remotely through crafted CSS elements in web pages.
CVE-2006-3450 is associated with remote code execution attacks leveraging JavaScript functions.