CVE-2007-5158
The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a file upload field, a related issue to CVE-2007-3511.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 15.01% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://osvdb.org/41382Broken Link
- http://secunia.com/advisories/27007Vendor Advisory
- http://www.0x000000.com/index.php?i=437Not Applicable
- http://www.securityfocus.com/bid/25836Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36848Third Party Advisory, VDB Entry
- http://osvdb.org/41382Broken Link
- http://secunia.com/advisories/27007Vendor Advisory
- http://www.0x000000.com/index.php?i=437Not Applicable
- http://www.securityfocus.com/bid/25836Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36848Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.