5.1
CVSSv2

CVE-2006-3281

Published: 28/06/2006 Updated: 23/07/2021
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted malicious users to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and whose extension contains the CLSID Key identifier for HTML Applications (HTA), aka "Folder GUID Code Execution Vulnerability." NOTE: directory traversal sequences were used in the original exploit, although their role is not clear.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 6.0

Exploits

source: wwwsecurityfocuscom/bid/19389/info Microsoft Windows is prone to a remote code-execution vulnerability This issue affects the Windows Explorer component This issue is caused by insecure handling of Drag and Drop events There is a public proof-of-concept that demonstrates that this vulnerability may be exploited to execute a ma ...