OSVDB ID: 27855

Title: Microsoft IE document.getElementByID Crafted CSS Arbitrary Code Execution

Info

Disclosure

Aug 08, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Microsoft Internet Explorer contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when a user accesses a malicious web site that contains JavaScript. It is possible that the flaw may allow to execute arbitrary code resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Private
Disclosure: OSVDB Verified

Solution

Microsoft has released a patch to address this issue. Additionally, it is possible to correct the flaw by implementing the following workaround(s): Disable active scripting.

Products

Microsoft Corporation

Internet Explorer

6

References

Credit

  • Sam Thomas -   -


Direct URL: http://osvdb.org/27855