CVE-2006-1192 describes an address bar spoofing vulnerability affecting Microsoft Internet Explorer versions 5.01 through 6, as well as specific Canon products utilizing IE components. This flaw allows remote attackers to conduct phishing attacks by manipulating the browser's trust UI, making it appear as though the user is on a legitimate site when they have navigated elsewhere. With a CVSS score of 2.6, it is considered low severity, requiring high attack complexity (AC:H) to achieve a partial integrity impact (I:P) without affecting confidentiality or availability. Despite its age, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.01CPE matchmatch criteria | cpe:2.3:a:microsoft:ie:5.01:windows_2000_sp4:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:microsoft:ie:6:*:windows_xp_professional_64bit:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:microsoft:ie:6:sp1:windows_xpsp1:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:microsoft:ie:6:windows_2000_sp4:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.