[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-2947Date: (C)2008-06-30   (M)2024-02-16


Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Property Cross-Domain Vulnerability." NOTE: according to Microsoft, CVE-2008-2948 and CVE-2008-2949 are duplicates of this issue, probably different attack vectors.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1020382
BID-29960
SECUNIA-30857
ADV-2008-1940
ADV-2008-2809
MS08-058
SSRT080143
TA08-288A
VU#923508
http://blogs.zdnet.com/security/?p=1348
http://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x02_0x04.txt
ie-location-locationhref-security-bypass(43366)
oval:org.mitre.oval:def:5901
win-ms08kb956390-update(45565)

CPE    3
cpe:/a:microsoft:internet_explorer:5.01:sp4
cpe:/a:microsoft:internet_explorer:6
cpe:/a:microsoft:internet_explorer:7
CWE    1
CWE-284
OVAL    2
oval:org.mitre.oval:def:5901
oval:org.secpod.oval:def:2631

© SecPod Technologies