Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2947

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2008-2947
Last Modified 07 Mar 2011 10:09:59
Published 30 Jun 2008 06:41:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-2947

Summary

Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Property Cross-Domain Vulnerability." NOTE: according to Microsoft, CVE-2008-2948 and CVE-2008-2949 are duplicates of this issue, probably different attack vectors.

Vulnerable Systems

Application

  • Microsoft Ie 6.0


References

CERT - TA08-288A

CERT-VN - VU#923508

XF - win-ms08kb956390-update(45565)

XF - ie-location-locationhref-security-bypass(43366)

VUPEN - ADV-2008-2809

VUPEN - ADV-2008-1940

SECTRACK - 1020382

BID - 29960

MISC - http://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x02_0x04.txt

MS - MS08-058

SECUNIA - 30857

HP - SSRT080143

MISC - http://blogs.zdnet.com/security/?p=1348

HP - HPSBST02379

Related Patches

MS08-058 Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB956390)

MS08-058 Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB956390)


Last Updated: 27 May 2016 10:49:54