Loading...
Loading...
Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and whose extension contains the CLSID Key identifier for HTML Applications (HTA), aka "Folder GUID Code Execution Vulnerability." NOTE: directory traversal sequences were used in the original exploit, although their role is not clear.
June 28, 2006
April 16, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-3281
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.