Lucene search

K
jvnJapan Vulnerability NotesJVN:62275332
HistoryDec 15, 2010 - 12:00 a.m.

JVN#62275332: Internet Explorer vulnerable to cross-site scripting

2010-12-1500:00:00
Japan Vulnerability Notes
jvn.jp
26

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.01

Percentile

83.3%

Microsoft Internet Explorer contains a vulnerability in handling Content-Type, which may result in cross-site scripting.

Impact

An arbitrary script may be executed.

Solution

Update the Software
Apply the latest update according to the information provided by Microsoft.

Products Affected

  • Internet Explorer 6 for Windows XP SP3
  • Internet Explorer 6 for Windows XP x64 Edition SP2
  • Internet Explorer 7 for Windows XP SP3
  • Internet Explorer 7 for Windows XP x64 Edition SP2
  • Internet Explorer 7 for Windows Vista SP1 and SP2
  • Internet Explorer 7 forWindows Vista x64 Edition SP1 and Windows Vista x64 Edition SP2
  • Internet Explorer 8 for Windows XP SP3
  • Internet Explorer 8 for Windows XP x64 Edition SP2
  • Internet Explorer 8 for Windows Vista SP1 and SP2
  • Internet Explorer 8 for Windows Vista x64 Edition SP1 and Windows Vista x64 Edition SP2
  • Internet Explorer 8 for Windows 7 and Windows 7 x64
    For more information, refer to the information provided by Microsoft.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.01

Percentile

83.3%