CVE-2006-3730 - CVSS 8.8

CVE-2006-3730

Published Date:21 July, 2006CWE-94
Last modified:16 June, 2026
Link:    CVE-2006-3730
NVD:   CVE-2006-3730
UBUNTU:   CVE-2006-3730
REDHAT:   CVE-2006-3730
EUVD: EUVD-2006-3724
CVSS scores for CVE-2006-3730
CVSS v3.1 : 8.8 HIGH
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
ScopeUnchanged
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
User InteractionRequired
CVSS v2 : 9.3 HIGH
Access VectorNetwork
Access ComplexityMedium
AuthenticationNone
 
Confidentiality ImpactComplete
Integrity ImpactComplete
Availability ImpactComplete
 
Threat Intelligence
  • Has Public Exploit: Yes
  • CISA KEV Release Date: N/A
  • CISA KEV Due Date: N/A
  • CISA KEV Required Action: N/A
Exploit Prediction in the next 30 days
63%
EPSS
Likely Exploited Vulnerabilities Probability
100%
LEV
Common Weakness Enumeration for CVE-2006-3730

CWE-94 : Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Products affected by CVE-2006-3730
Configuration 1:
Running on ALL of the following:
Any of the following configurations:
ie
cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
OR
internet_explorer
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
Running on:
windows_xp
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
References