Information disclosure vulnerability in Internet Explorer due to improper event-handlingID: oval:org.mitre.oval:def:13255 | Date: (C)2011-10-25 (M)2022-04-14 |
Class: VULNERABILITY | Family: windows |
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability."
Platform: |
Microsoft Windows 2000 |
Microsoft Windows Server 2003 |
Microsoft Windows Server 2008 |
Microsoft Windows Vista |
Microsoft Windows XP |
Product: |
Microsoft Internet Explorer 6 |
Microsoft Internet Explorer 7 |