U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2007-3576

Change History

CVE Modified by MITRE 11/06/2023 9:00:51 PM

Action Type Old Value New Value
Changed Description
** DISPUTED **  Microsoft Internet Explorer 6 executes web script from URIs of arbitrary scheme names ending with the "script" character sequence, using the (1) vbscript: handler for scheme names with 7 through 9 characters, and the (2) javascript: handler for scheme names with 10 or more characters, which might allow remote attackers to bypass certain XSS protection schemes.  NOTE: other researchers dispute the significance of this issue, stating "this only works when typed in the address bar."
Microsoft Internet Explorer 6 executes web script from URIs of arbitrary scheme names ending with the "script" character sequence, using the (1) vbscript: handler for scheme names with 7 through 9 characters, and the (2) javascript: handler for scheme names with 10 or more characters, which might allow remote attackers to bypass certain XSS protection schemes.  NOTE: other researchers dispute the significance of this issue, stating "this only works when typed in the address bar.
Added Reference

								
							
							
						
MITRE http://sla.ckers.org/forum/read.php?2%2C13209%2C13218 [No types assigned]
Removed Reference
MITRE http://sla.ckers.org/forum/read.php?2,13209,13218