Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-3472
StatusCandidate
DescriptionMicrosoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "HTML Element Cross-Domain Vulnerability."
SeverityHigh
CVSS score9,3
CVSS vector(AV:N/AC:M/Au:N/C:C/I:C/A:C)
PhaseAssigned (26.01.2012)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3472
ReferencesBID : 31615
 BID : 31654
 CERT : TA08-288A
 HP : HPSBST02379
 HP : SSRT080143
 MS : MS08-058
 SECTRACK : 1021047
 VUPEN : ADV-2008-2809
 XF : ie-element-security-bypass(45558)
 XF : win-ms08kb956390-update(45565)
SecurityVulns:Microsoft Internet Explorer multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server