← All CVEs

CVE-2006-2900

medium · 4

Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.

4
CVSS
12.6%
EPSS (exploit prob.)
96th
EPSS percentile
2006-06-07
Published

AV:N/AC:H/Au:N/C:P/I:P/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
microsoftie5.01
microsoftie6
microsoftie6
microsoftie6
microsoftie6
microsoftie6
microsoftie6
microsoftie6
microsoftie6
microsoftie6
canonnetwork_camera_server_vb101all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-2900