First published: Tue Oct 03 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an explicit charset, a related issue to CVE-2006-0032.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6.0.2900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5152 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2006-5152, users are advised to upgrade to a more recent version of Internet Explorer or apply relevant security patches provided by Microsoft.
CVE-2006-5152 specifically affects Microsoft Internet Explorer version 6.0.2900.
CVE-2006-5152 enables remote attackers to execute cross-site scripting (XSS) via UTF-7 encoded URLs.
Yes, CVE-2006-5152 is related to CVE-2006-0032 as both involve issues with character encoding in Internet Explorer.