Revision Date: | 2014-08-18 | Version: | 53 | Title: | HTML Element Cross-Domain Vulnerability | Description: | Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability." | Family: | windows | Class: | vulnerability | Status: | ACCEPTED | Reference(s): | CVE-2010-0494
| Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows XP
| Product(s): | Microsoft Internet Explorer 6 Microsoft Internet Explorer 7 Microsoft Internet Explorer 8
| Definition Synopsis | Internet Explorer 6 on Windows 2000 - RTMGDR Microsoft Windows 2000 is installed
AND Microsoft Internet Explorer 6 is installed
AND Mshtml.dll version is less than 6.0.2800.1646
OR Internet Explorer 6 on XP x86
Microsoft Windows XP (32-bit) is installed
AND Microsoft Internet Explorer 6 is installed
AND Mshtml.dll version is less than 6.0.2900.3676
OR Internet Explorer 6 on XP x86
Microsoft Windows XP (32-bit) is installed
AND Microsoft Internet Explorer 6 is installed
AND Mshtml.dll version is less than 6.0.2900.5945
OR Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64
XP x64/server 2003 x86/x64/ia64
Microsoft Windows XP x64 is installed
OR Microsoft Windows Server 2003 (32-bit) is installed
OR Microsoft Windows Server 2003 (x64) is installed
OR Microsoft Windows Server 2003 (ia64) Gold is installed
AND Microsoft Internet Explorer 6 is installed
AND Mshtml.dll version is less than 6.0.3790.4672
OR Internet Explorer 7 on XP x86/x64 - GDR
XP x86/x64
Microsoft Windows XP (32-bit) is installed
OR Microsoft Windows XP x64 is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6000.16000
AND Mshtml.dll version is less than 7.0.6000.17023
OR Internet Explorer 7 on XP x86/x64 - QFE
XP x86/x64
Microsoft Windows XP (32-bit) is installed
OR Microsoft Windows XP x64 is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6000.20000
AND Mshtml.dll version is less than 7.0.6000.21228
OR Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR
Server 2003 x86/x64/ia64
Microsoft Windows Server 2003 (32-bit) is installed
OR Microsoft Windows Server 2003 (x64) is installed
OR Microsoft Windows Server 2003 (ia64) Gold is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6000.16000
AND Mshtml.dll version is less than 7.0.6000.17023
OR Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE
Server 2003 x86/x64/ia64
Microsoft Windows Server 2003 (32-bit) is installed
OR Microsoft Windows Server 2003 (x64) is installed
OR Microsoft Windows Server 2003 (ia64) Gold is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6000.20000
AND Mshtml.dll version is less than 7.0.6000.21228
OR Internet Explorer 7 on Vista x86/x64 - GDR
Vista x86/x64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6000.16000
AND Mshtml.dll version is less than 7.0.6000.17037
OR Internet Explorer 7 on Vista x86/x64 - LDR
Vista x86/x64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6000.20000
AND Mshtml.dll version is less than 7.0.6000.21242
OR Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR
Vista x86/x64, Server 2008 x86/x64/ia64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
OR Microsoft Windows Server 2008 (ia-64) is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6001.16000
AND Mshtml.dll version is less than 7.0.6001.18444
OR Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR
Vista x86/x64, Server 2008 x86/x64/ia64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
OR Microsoft Windows Server 2008 (ia-64) is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6001.20000
AND Mshtml.dll version is less than 7.0.6001.22653
OR Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR
Vista x86/x64, Server 2008 x86/x64/ia64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
OR Microsoft Windows Server 2008 (ia-64) is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6002.18000
AND Mshtml.dll version is less than 7.0.6002.18226
OR Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR
Vista x86/x64, Server 2008 x86/x64/ia64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
OR Microsoft Windows Server 2008 (ia-64) is installed
AND Microsoft Internet Explorer 7 is installed
AND Mshtml.dll version is greater than 7.0.6002.22000
AND Mshtml.dll version is less than 7.0.6002.22360
OR Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64 - GDR
XP x86/x64, Server 2003 x86/x64
Microsoft Windows XP (32-bit) is installed
OR Microsoft Windows XP x64 is installed
OR Microsoft Windows Server 2003 (32-bit) is installed
OR Microsoft Windows Server 2003 (x64) is installed
AND Microsoft Internet Explorer 8 is installed
AND Mshtml.dll version is greater than 8.0.6001.18000
AND Mshtml.dll version is less than 8.0.6001.18904
OR Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR
XP x86/x64, Server 2003 x86/x64
Microsoft Windows XP (32-bit) is installed
OR Microsoft Windows XP x64 is installed
OR Microsoft Windows Server 2003 (32-bit) is installed
OR Microsoft Windows Server 2003 (x64) is installed
AND Microsoft Internet Explorer 8 is installed
AND Mshtml.dll version is greater than 8.0.6001.22000
AND Mshtml.dll version is less than 8.0.6001.22995
OR Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR
Vista x86/x64, Server 2008 x86/x64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
AND Microsoft Internet Explorer 8 is installed
AND Mshtml.dll version is greater than 8.0.6001.18000
AND Mshtml.dll version is less than 8.0.6001.18904
OR Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR
Vista x86/x64, all Server 2008 x86/x64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
AND Microsoft Internet Explorer 8 is installed
AND Mshtml.dll version is greater than 8.0.6001.22000
AND Mshtml.dll version is less than 8.0.6001.22995
OR Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR
7 x86/x64, Server 2008 R2 x64/ia64
Microsoft Windows 7 (32-bit) is installed
OR Microsoft Windows 7 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
AND Microsoft Internet Explorer 8 is installed
AND Mshtml.dll version is greater than or equal 8.0.7600.16000
AND Mshtml.dll version is less than 8.0.7600.16535
OR Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR
7 x86/x64, Server 2008 R2 x64/ia64
Microsoft Windows 7 (32-bit) is installed
OR Microsoft Windows 7 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
AND Microsoft Internet Explorer 8 is installed
AND Mshtml.dll version is greater than or equal 8.0.7600.20000
AND Mshtml.dll version is less than 8.0.7600.20651
|
|