CVE-2009-4074 Information

Description

The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the \response-changing mechanism\ to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities related to the details of output encoding and improper modification of an HTML attribute aka \XSS Filter Script Handling Vulnerability.\

Reference

http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/ http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf http://www.securityfocus.com/bid/37135 http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/ https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A7715

Share on: