Vulnerability Name: | CVE-2008-2281 (CCN-42416) | ||||||||
Assigned: | 2008-05-14 | ||||||||
Published: | 2008-05-14 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 8.0 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:U/RC:UR)
4.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Aviv Raff On .NET Advisories, Wednesday, May 14, 2008 Internet Explorer "Print Table of Links" Cross-Zone Scripting Vulnerability Source: MISC Type: Exploit http://aviv.raffon.net/2008/05/14/InternetExplorerQuotPrintTableOfLinksquotCrossZoneScriptingVulnerability.aspx Source: MITRE Type: CNA CVE-2008-2281 Source: CCN Type: SA30141 Internet Explorer "Print Table of Links" Cross-Zone Scripting Source: SECUNIA Type: Vendor Advisory 30141 Source: CCN Type: Microsoft Internet Explorer Web site Internet Explorer: Home Page Source: CCN Type: OSVDB ID: 45074 Microsoft IE Print Table of Links Cross-Zone Scripting Source: BID Type: UNKNOWN 29217 Source: CCN Type: BID-29217 Microsoft Internet Explorer 'Print Table of Links' Cross Zone Script Injection Vulnerability Source: VUPEN Type: UNKNOWN ADV-2008-1529 Source: XF Type: UNKNOWN ie-printtableoflinks-code-execution(42416) Source: XF Type: UNKNOWN ie-printtableoflinks-code-execution(42416) Source: EXPLOIT-DB Type: UNKNOWN 5619 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |