[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Information disclosure vulnerability in scripting engines - MS11-009

ID: oval:org.secpod.oval:def:1034Date: (C)2011-05-23   (M)2022-03-15
Class: PATCHFamily: windows




The host is missing an Important security update according to Microsoft security bulletin, MS11-009. The update is required to fix information disclosure vulnerability in JScript and VBScript scripting engines. A flaw is present in the JScript and VBScript scripting engines, which fails to properly load decoded scripts obtained from web pages. Successful exploitation could allow remote attackers to redirect a user to the attacker's web site.

Platform:
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Product:
Microsoft VBScript 5.8
Microsoft JScript 5.8
Reference:
MS11-009
CVE-2011-0031
CVE    1
CVE-2011-0031
CPE    12
cpe:/o:microsoft:windows_server_2008:r2:sp1:x64
cpe:/o:microsoft:windows_7::sp1:x64
cpe:/o:microsoft:windows_7::sp1:x86
cpe:/o:microsoft:windows_7:::x64
...
XCCDF    4
xccdf_com.secpod_benchmark_microsoft-windows-server-2008
xccdf_com.secpod_benchmark_microsoft-windows-7
xccdf_com.secpod_benchmark_microsoft-windows-server-2008-r2
xccdf_scaprepo.com_benchmark_microsoft-windows-server-2008-r2
...

© SecPod Technologies