[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-4089Date: (C)2005-12-08   (M)2023-12-22


Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.1
Exploit Score: 8.6
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1016291
BID-15660
SECUNIA-17564
ADV-2005-2804
ADV-2006-2319
MS06-021
http://www.hacker.co.il/security/ie/css_import.html
oval:org.mitre.oval:def:1556
oval:org.mitre.oval:def:1800
oval:org.mitre.oval:def:1838
oval:org.mitre.oval:def:1914
oval:org.mitre.oval:def:1977
oval:org.mitre.oval:def:1985

CWE    1
CWE-264
OVAL    6
oval:org.mitre.oval:def:1914
oval:org.mitre.oval:def:1977
oval:org.mitre.oval:def:1838
oval:org.mitre.oval:def:1800
...

© SecPod Technologies