Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2949

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2008-2949
Last Modified 07 Mar 2011 10:09:59
Published 30 Jun 2008 06:41:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-2949

Summary

Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.

Vulnerable Systems

Application

  • Microsoft Ie 6

  • Microsoft Ie 7


References

CERT-VN - VU#516627

VUPEN - ADV-2008-1941

MISC - http://technet.microsoft.com/en-us/security/cc405107.aspx#EHD

MISC - http://sirdarckcat.blogspot.com/2008/05/browsers-ghost-busters.html

MISC - http://blogs.zdnet.com/security/?p=1348


Last Updated: 27 May 2016 10:48:02