[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-2949Date: (C)2008-06-30   (M)2023-12-22


Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
ADV-2008-1941
VU#516627
http://blogs.zdnet.com/security/?p=1348
http://sirdarckcat.blogspot.com/2008/05/browsers-ghost-busters.html
http://technet.microsoft.com/en-us/security/cc405107.aspx#EHD

CPE    2
cpe:/a:microsoft:internet_explorer:6
cpe:/a:microsoft:internet_explorer:7

© SecPod Technologies