Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-1114

Опубликовано: 26 фев. 2007
Источник: nvd
CVSS2: 4.3
EPSS Средний

Описание

The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:microsoft:ie:7.0:*:vista:*:*:*:*:*

EPSS

Процентиль: 95%
0.20968
Средний

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.

EPSS

Процентиль: 95%
0.20968
Средний

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other