First published: Wed Aug 09 2006(Updated: )
Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between pages, which allows remote attackers to obtain the window location of visited web pages in other domains or zones, aka "Window Location Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6-windows_server_2003_sp1 | |
Internet Explorer | =5.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3640 is classified as a medium severity vulnerability.
To mitigate CVE-2006-3640, users should upgrade to a newer version of Internet Explorer that is not affected by this vulnerability.
CVE-2006-3640 exploits the ability of scripts to persist across navigations, allowing information disclosure about visited web pages.
CVE-2006-3640 affects Microsoft Internet Explorer 5.01 and 6, specifically on Windows Server 2003 SP1.
CVE-2006-3640 can facilitate window location information disclosure attacks, potentially compromising user privacy.