Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) script tag; (2) data attribute of an object tag; (3) value attribute of a param tag; (4) background attribute of a body tag; or (5) the background:url attribute declared in the BODY parameter of a STYLE tag.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T14:14:12.948Z
Reserved: 2007-06-26T00:00:00
Link: CVE-2007-3406
No data.
Status : Deferred
Published: 2007-06-26T18:30:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-3406
No data.
OpenCVE Enrichment
No data.
Weaknesses