AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-4560

HIGH · CVSS 7.5 EPSS 18.26%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-09-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-4560
Severity
HIGH
CVSS
7.5
EPSS
18.26%
Windows Java

Original NVD Description

Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.