Vulnerability Name: | CVE-2008-5551 (CCN-47277) | ||||||||
Assigned: | 2008-12-11 | ||||||||
Published: | 2008-12-11 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Dec 11 2008 - 10:27:43 CST Aspect9: Internet Explorer 8.0 Beta 2 Anti-XSS Filter Vulnerabilities Source: MITRE Type: CNA CVE-2008-5551 Source: SREASON Type: UNKNOWN 4724 Source: CCN Type: Microsoft Internet Explorer Web site Windows Internet Explorer 8 Source: CCN Type: OSVDB ID: 57062 Microsoft IE STYLE Element / CSS Expression Property Double Content Injection XSS Filter Bypass Source: BUGTRAQ Type: UNKNOWN 20081211 Aspect9: Internet Explorer 8.0 Beta 2 Anti-XSS Filter Vulnerabilities Source: BID Type: Exploit 32780 Source: CCN Type: BID-32780 Internet Explorer 8 CSS 'expression' Property Cross Site Scripting Filter Bypass Weakness Source: XF Type: UNKNOWN ie-xss-filter-bypass(47277) Source: XF Type: UNKNOWN ie-antixss-xss(47277) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |