Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-2947
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-2947

Description:
Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Property Cross-Domain Vulnerability." NOTE: according to Microsoft, CVE-2008-2948 and CVE-2008-2949 are duplicates of this issue, probably different attack vectors.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/43366
  http://xforce.iss.net/xforce/xfdb/45565

ST
  1020382

SAID
  Secunia Advisory: SA30857

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5901

MS
  http://www.microsoft.com/technet/security/Bulletin/MS08-058.mspx

MISC
  http://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x02_0x04.txt
  http://blogs.zdnet.com/security/?p=1348

HP
  http://marc.info/?l=bugtraq&m=122479227205998&w=2

CERT-VN
  923508

CERT
  http://www.us-cert.gov/cas/techalerts/TA08-288A.html

BID
  29960


Return to the previous page.