Title : W3C Amaya Browser HTML Tags Handling Remote Code Execution Vulnerabilities VUPEN ID : VUPEN/ADV-2006-1351 CVE ID : CVE-2006-1900
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-04-13
Technical Description
Multiple vulnerabilities have been identified in W3C Amaya, which could be exploited by remote attackers to take complete control of an affected system. These flaws are due to buffer overflow errors when processing overly long attributes (e.g. compact, rows, or color) associated with HTML elements (e.g. colgroup, textarea, or legend), which could be exploited by remote attackers to execute arbitrary commands via a specially crafted web page.