Описание
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability."
Ссылки
- Mailing ListRelease NotesThird Party Advisory
- PatchThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
- Broken Link
- PatchVendor Advisory
- VDB Entry
- VDB Entry
- Third Party Advisory
- Mailing ListRelease NotesThird Party Advisory
- PatchThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
- Broken Link
- PatchVendor Advisory
- VDB Entry
- VDB Entry
- Third Party Advisory
Уязвимые конфигурации
Одновременно
Одновременно
Одно из
Одновременно
Одновременно
Одно из
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability."
EPSS
9.3 Critical
CVSS2