CVE-2008-2948

Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*

History

21 Nov 2024, 00:48

Type Values Removed Values Added
References () http://blogs.zdnet.com/security/?p=1348 - () http://blogs.zdnet.com/security/?p=1348 -
References () http://secunia.com/advisories/30851 - Vendor Advisory () http://secunia.com/advisories/30851 - Vendor Advisory
References () http://sirdarckcat.blogspot.com/2008/05/ghosts-for-ie8-and-ie75730.html - () http://sirdarckcat.blogspot.com/2008/05/ghosts-for-ie8-and-ie75730.html -
References () http://technet.microsoft.com/en-us/security/cc405107.aspx#EHD - () http://technet.microsoft.com/en-us/security/cc405107.aspx#EHD -
References () http://www.gnucitizen.org/blog/ghost-busters/ - () http://www.gnucitizen.org/blog/ghost-busters/ -
References () http://www.kb.cert.org/vuls/id/516627 - US Government Resource () http://www.kb.cert.org/vuls/id/516627 - US Government Resource
References () http://www.vupen.com/english/advisories/2008/1941/references - () http://www.vupen.com/english/advisories/2008/1941/references -

Information

Published : 2008-06-30 22:41

Updated : 2024-11-21 00:48


NVD link : CVE-2008-2948

Mitre link : CVE-2008-2948

CVE.ORG link : CVE-2008-2948


JSON object : View

Products Affected

microsoft

  • internet_explorer