Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2948

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2008-2948
Last Modified 07 Mar 2011 10:09:59
Published 30 Jun 2008 06:41:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-2948

Summary

Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.

Vulnerable Systems

Application

  • Microsoft Ie 7

  • Microsoft Internet Explorer 8


References

CERT-VN - VU#516627

VUPEN - ADV-2008-1941

MISC - http://www.gnucitizen.org/blog/ghost-busters/

MISC - http://technet.microsoft.com/en-us/security/cc405107.aspx#EHD

MISC - http://sirdarckcat.blogspot.com/2008/05/ghosts-for-ie8-and-ie75730.html

SECUNIA - 30851

MISC - http://blogs.zdnet.com/security/?p=1348


Last Updated: 27 May 2016 10:48:02