Microsoft Internet Explorer Position CSS Denial of Service Vulnerability
BID:17932
Info
Microsoft Internet Explorer Position CSS Denial of Service Vulnerability
| Bugtraq ID: | 17932 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-7031 |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | seven is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Position CSS Denial of Service Vulnerability
Microsoft Internet Explorer is affected by a denial-of-service vulnerability. This issue arises because the application fails to handle exceptional conditions in a proper manner.
An attacker may exploit this issue by enticing a user to visit a malicious site, resulting in a denial-of-service condition in the application.
Since exploiting this issue requires only standard HTML and CSS, it may not be easily mitigated.
Internet Explorer 6 is vulnerable to this issue; other versions may also be affected.
Microsoft Internet Explorer is affected by a denial-of-service vulnerability. This issue arises because the application fails to handle exceptional conditions in a proper manner.
An attacker may exploit this issue by enticing a user to visit a malicious site, resulting in a denial-of-service condition in the application.
Since exploiting this issue requires only standard HTML and CSS, it may not be easily mitigated.
Internet Explorer 6 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Microsoft Internet Explorer Position CSS Denial of Service Vulnerability
The following HTML content is sufficient to trigger this issue:
The following HTML content is sufficient to trigger this issue:
Solution / Fix
Microsoft Internet Explorer Position CSS Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Microsoft Internet Explorer Position CSS Denial of Service Vulnerability
References:
References: