CVE-2006-1191
Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.
- Affected products
- Internet Explorer
- Microsoft Internet Explorer
- = 5.01, 5.1, 5.5, 6.0
- Fix
- Available
- CVSS 2.0
- 4.0 MEDIUM
- EPSS
- 31.6% (98th percentile)
- NVD status
- Modified
- Published
- 2006-04-11
CVE-2006-1191 at NVD
1 known exploit for CVE-2006-1191
Proof-of-concept code and exploit modules indexed by Sploitus