CVE-2006-2900

Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:5.01:windows_2000_sp4:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:*:windows_xp_professional_64bit:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:sp1:windows_98:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:sp1:windows_98_se:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:sp1:windows_millennium:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:sp1:windows_xpsp1:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:windows_2000_sp4:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:windows_xp_sp2:*:*:*:*:*:*
cpe:2.3:h:canon:network_camera_server_vb101:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:12

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046610.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046610.html -
References () http://secunia.com/advisories/20449 - Vendor Advisory () http://secunia.com/advisories/20449 - Vendor Advisory
References () http://securityreason.com/securityalert/1059 - () http://securityreason.com/securityalert/1059 -
References () http://www.securityfocus.com/bid/18308 - () http://www.securityfocus.com/bid/18308 -
References () http://www.vupen.com/english/advisories/2006/2161 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/2161 - Vendor Advisory

Information

Published : 2006-06-07 16:02

Updated : 2024-11-21 00:12


NVD link : CVE-2006-2900

Mitre link : CVE-2006-2900

CVE.ORG link : CVE-2006-2900


JSON object : View

Products Affected

canon

  • network_camera_server_vb101

microsoft

  • ie
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor