First published: Tue Jun 26 2007(Updated: )
Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) script tag; (2) data attribute of an object tag; (3) value attribute of a param tag; (4) background attribute of a body tag; or (5) the background:url attribute declared in the BODY parameter of a STYLE tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp2 | |
Internet Explorer | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3406 is classified as a critical vulnerability due to its potential for remote exploitation leading to unauthorized file access.
To mitigate CVE-2007-3406, users should upgrade to a more secure version of Internet Explorer or apply any relevant security updates provided by Microsoft.
CVE-2007-3406 primarily affects Microsoft Internet Explorer version 6 running on Windows XP Service Pack 2.
Yes, CVE-2007-3406 can be exploited remotely by attackers through crafted web pages that leverage the file: URI scheme.
CVE-2007-3406 involves multiple HTML tags including bgsound, input, EMBED, img, and script tags that can be manipulated to perform path traversal.