Vulnerability Description
Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Firefox might allow remote attackers to modify the visual presentation of web pages and possibly bypass protection mechanisms such as content filters via ASCII characters with the 8th bit set, which could be stripped by Internet Explorer to render legible text, but not when using other browsers. NOTE: there has been significant discussion about this issue, and as of 20060625, it is not clear where the responsibility for this issue lies, although it might be due to vagueness within the associated standards. NOTE: this might only be exploitable with certain encodings.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Explorer | 6.0.2900 |
References
- http://ha.ckers.org/blog/20060621/malformed-ascii-bypasses-filters/
- http://ha.ckers.org/blog/20060621/us-ascii-xss-part-2
- http://www.osvdb.org/28376
- http://www.securityfocus.com/archive/1/437948/100/0/threaded
- http://www.securityfocus.com/archive/1/438049/100/0/threaded
- http://www.securityfocus.com/archive/1/438051/100/0/threaded
- http://www.securityfocus.com/archive/1/438066/100/0/threaded
- http://www.securityfocus.com/archive/1/438154/100/0/threaded
- http://www.securityfocus.com/archive/1/438163/100/0/threaded
- http://www.securityfocus.com/archive/1/438358/100/0/threaded
- http://www.securityfocus.com/archive/1/438359/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27288
- http://ha.ckers.org/blog/20060621/malformed-ascii-bypasses-filters/
- http://ha.ckers.org/blog/20060621/us-ascii-xss-part-2
- http://www.osvdb.org/28376
FAQ
What is CVE-2006-3227?
CVE-2006-3227 is a vulnerability with a CVSS score of 2.6 (LOW). Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Firefox might allow remote attackers to modify the visual presentation of web pages and possibly by...
How severe is CVE-2006-3227?
CVE-2006-3227 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3227?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Internet Explorer.