CVE-2008-5555
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
Microsoft Internet Explorer 8.0 Beta 2 confía en la cabecera HTTP XDomainRequestAllowed para autorizar el intercambio de datos entre dominios, o que permite a atacantes remotos evitar el mecanismo de protección del producto XSS Filter y dirigir ataques XSS (ejecución de secuencias de comandos en sitios cruzados) y de dominios cruzados, mediante la inyección de esta cabecera después de una secuencia CRLF, relacionado con "XDomainRequest Allowed Injection (XAI)." NOTA: El fabricante mantiene que el filtro XSS de manera intencionada no intenta "abordar todas las hipótesis de ataque XSS".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-12-12 CVE Reserved
- 2008-12-12 CVE Published
- 2024-07-28 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/499124/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/47277 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/47444 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Internet Explorer Search vendor "Microsoft" for product "Internet Explorer" | 8 Search vendor "Microsoft" for product "Internet Explorer" and version "8" | beta2 |
Affected
|