Vulnerability Name: | CVE-2008-2947 (CCN-43366) | ||||||||
Assigned: | 2008-06-26 | ||||||||
Published: | 2008-06-26 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Property Cross-Domain Vulnerability." Note: according to Microsoft, CVE-2008-2948 and CVE-2008-2949 are duplicates of this issue, probably different attack vectors. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-284 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MISC Type: Press/Media Coverage http://blogs.zdnet.com/security/?p=1348 Source: MITRE Type: CNA CVE-2008-2947 Source: HP Type: Mailing List SSRT080143 Source: CCN Type: SA30857 Internet Explorer 6 Window "location" Handling Vulnerability Source: SECUNIA Type: Permissions Required, Vendor Advisory 30857 Source: CCN Type: SECTRACK ID: 1020382 Microsoft Internet Explorer Lets Remote Users Conduct Cross-Domain Scripting Attacks Source: CCN Type: ASA-2008-411 MS08-058 Cumulative Security Update for Internet Explorer (956390) Source: CCN Type: NORTEL BULLETIN ID: 2008009123, Rev 1 Nortel Response to Microsoft Security Bulletin MS08-058 Source: CCN Type: US-CERT VU#923508 Microsoft Internet Explorer 6 contains a cross-domain vulnerability Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#923508 Source: CCN Type: Microsoft Security Bulletin MS08-058 Cumulative Security Update for Internet Explorer (956390) Source: CCN Type: Microsoft Security Bulletin MS08-073 Cumulative Security Update for Internet Explorer (958215) Source: CCN Type: Microsoft Security Bulletin MS09-002 Cumulative Security Update for Internet Explorer (961260) Source: CCN Type: Microsoft Security Bulletin MS09-014 Cumulative Security Update for Internet Explorer (963027) Source: CCN Type: Ph4nt0m Security Team Advisory Issue 0x02, Phile #0x04 of 0x0A Source: MISC Type: Exploit http://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x02_0x04.txt Source: BID Type: Third Party Advisory, VDB Entry 29960 Source: CCN Type: BID-29960 Microsoft Internet Explorer 'location' & 'location.href' Cross Domain Security Bypass Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1020382 Source: CERT Type: Third Party Advisory, US Government Resource TA08-288A Source: VUPEN Type: Broken Link ADV-2008-1940 Source: VUPEN Type: Broken Link ADV-2008-2809 Source: MS Type: UNKNOWN MS08-058 Source: XF Type: UNKNOWN ie-location-locationhref-security-bypass(43366) Source: XF Type: UNKNOWN ie-location-locationhref-security-bypass(43366) Source: XF Type: UNKNOWN win-ms08kb956390-update(45565) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5901 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |