Vulnerabilities > CVE-2006-1388 - Unspecified vulnerability in Microsoft IE and Internet Explorer
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | MS Internet Explorer (HTML Tag) Memory Corruption (MS06-013). CVE-2006-1185,CVE-2006-1186,CVE-2006-1188,CVE-2006-1189,CVE-2006-1190,CVE-2006-1191,CVE-2006-11... |
id | EDB-ID:1838 |
last seen | 2016-01-31 |
modified | 2006-05-27 |
published | 2006-05-27 |
reporter | Thomas Waldegger |
source | https://www.exploit-db.com/download/1838/ |
title | Microsoft Internet Explorer HTML Tag Memory Corruption MS06-013 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-013.NASL |
description | The remote host is missing IE Cumulative Security Update 912812. The remote version of IE is vulnerable to several flaws that could allow an attacker to execute arbitrary code on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21210 |
published | 2006-04-11 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21210 |
title | MS06-013: Cumulative Security Update for Internet Explorer (912812) |
Oval
accepted 2011-05-16T04:01:22.728-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Dragos Prisaca organization Gideon Technologies, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors. family windows id oval:org.mitre.oval:def:1591 status accepted submitted 2006-04-12T12:55:00.000-04:00 title IE6 HTA Execution Vulnerability (WinXP) version 69 accepted 2014-02-24T04:00:21.410-05:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Matthew Wojcik organization The MITRE Corporation name Preeti Subramanian organization SecPod Technologies name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc. name Maria Mikhno organization ALTX-SOFT
description Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors. family windows id oval:org.mitre.oval:def:1642 status accepted submitted 2006-04-12T12:55:00.000-04:00 title IE6 HTA Execution Vulnerability (Win2K/XP,SP1) version 73 accepted 2011-05-16T04:01:33.652-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors. family windows id oval:org.mitre.oval:def:1676 status accepted submitted 2006-04-12T12:55:00.000-04:00 title IE6 HTA Execution Vulnerability (Server 2003,SP1) version 68 accepted 2011-05-16T04:01:39.935-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Jonathan Baker organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors. family windows id oval:org.mitre.oval:def:1724 status accepted submitted 2006-04-12T12:55:00.000-04:00 title IE6 HTA Execution Vulnerability (Server 2003) version 68 accepted 2014-02-24T04:00:23.505-05:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Robert L. Hollis organization ThreatGuard, Inc. name Anna Min organization BigFix, Inc name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc. name Maria Mikhno organization ALTX-SOFT
description Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors. family windows id oval:org.mitre.oval:def:1774 status accepted submitted 2006-04-12T12:55:00.000-04:00 title IE5 HTA Execution Vulnerability (Win2K) version 71
References
- http://jeffrey.vanderstad.net/grasshopper/
- http://news.zdnet.com/2100-1009_22-6052396.html?tag=zdfd.newsfeed
- http://www.securityfocus.com/bid/17181
- http://securitytracker.com/id?1015800
- http://www.osvdb.org/24095
- http://secunia.com/advisories/19378
- http://www.us-cert.gov/cas/techalerts/TA06-101A.html
- http://www.kb.cert.org/vuls/id/434641
- http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1415.html
- http://www.vupen.com/english/advisories/2006/1318
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25394
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1774
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1724
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1676
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1642
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1591
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-013