Yahoo Toolbar Internet Explorer 6 Policy Bypass
| TSL ID | FSC20100726-06 |
| CVE ID(s) | Not available. |
| Severity | Moderate |
| Description | A policy bypass situation may occur when Yahoo! Toolbar is installed on a Windows host. More specifically, the installation of Yahoo! Toolbar changes the security context of the Internet Explorer 6 in a way that it allows the execution of "Run" method of the "WScript.Shell" from a remote web page. This can be leveraged by remote attackers to execute arbitrary commands on the target host via enticing the target user to open a crafted HTML page. The commands would run within the security context of the logged in user. |
| Affected Products |
|
| CVSS Score |
Base 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P):
|