Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-2947
StatusCandidate
DescriptionCross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Property Cross-Domain Vulnerability." NOTE: according to Microsoft, CVE-2008-2948 and CVE-2008-2949 are duplicates of this issue, probably different attack vectors.
PhaseAssigned (30.06.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2947
ReferencesBID : 29960
 CERT-VN : VU#923508
 CERT : TA08-288A
 HP : HPSBST02379
 HP : SSRT080143
 MISC : http://blogs.zdnet.com/security/?p=1348
 MISC : http://www.ph4nt0m.org-a.googlepages.com/PSTZine_0...
 MS : MS08-058
 OVAL : oval:org.mitre.oval:def:5901
 SECTRACK : 1020382
 SECUNIA : 30857
 VUPEN : ADV-2008-1940
 VUPEN : ADV-2008-2809
 XF : ie-location-locationhref-security-bypass(43366)
 XF : win-ms08kb956390-update(45565)
SecurityVulns:Microsoft Internet Explorer multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server