Lucene search

K
nvd[email protected]NVD:CVE-2011-2382
HistoryJun 03, 2011 - 5:55 p.m.

CVE-2011-2382

2011-06-0317:55:00
CWE-20
web.nvd.nist.gov
8

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.012

Percentile

85.4%

Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a โ€œcookiejackingโ€ issue.

Affected configurations

Nvd
Node
microsoftieMatch9beta
OR
microsoftinternet_explorerRangeโ‰ค8
OR
microsoftinternet_explorerMatch3.0
OR
microsoftinternet_explorerMatch3.0.1
OR
microsoftinternet_explorerMatch3.0.2
OR
microsoftinternet_explorerMatch3.1
OR
microsoftinternet_explorerMatch3.2
OR
microsoftinternet_explorerMatch4.0
OR
microsoftinternet_explorerMatch4.0.1
OR
microsoftinternet_explorerMatch4.0.1sp1
OR
microsoftinternet_explorerMatch4.0.1sp2
OR
microsoftinternet_explorerMatch4.01
OR
microsoftinternet_explorerMatch4.1
OR
microsoftinternet_explorerMatch4.01sp1
OR
microsoftinternet_explorerMatch4.5
OR
microsoftinternet_explorerMatch4.40.308
OR
microsoftinternet_explorerMatch4.40.520
OR
microsoftinternet_explorerMatch4.70.1155
OR
microsoftinternet_explorerMatch4.70.1158
OR
microsoftinternet_explorerMatch4.70.1215
OR
microsoftinternet_explorerMatch4.70.1300
OR
microsoftinternet_explorerMatch4.71.544
OR
microsoftinternet_explorerMatch4.71.1008.3
OR
microsoftinternet_explorerMatch4.71.1712.6
OR
microsoftinternet_explorerMatch4.72.2106.8
OR
microsoftinternet_explorerMatch4.72.3110.8
OR
microsoftinternet_explorerMatch4.72.3612.1713
OR
microsoftinternet_explorerMatch5
OR
microsoftinternet_explorerMatch5.0
OR
microsoftinternet_explorerMatch5.0.1
OR
microsoftinternet_explorerMatch5.0.1sp1
OR
microsoftinternet_explorerMatch5.0.1sp2
OR
microsoftinternet_explorerMatch5.0.1sp3
OR
microsoftinternet_explorerMatch5.0.1sp4
OR
microsoftinternet_explorerMatch5.00.0518.10
OR
microsoftinternet_explorerMatch5.00.0910.1309
OR
microsoftinternet_explorerMatch5.00.2014.0216
OR
microsoftinternet_explorerMatch5.00.2314.1003
OR
microsoftinternet_explorerMatch5.00.2516.1900
OR
microsoftinternet_explorerMatch5.00.2614.3500
OR
microsoftinternet_explorerMatch5.00.2919.800
OR
microsoftinternet_explorerMatch5.00.2919.3800
OR
microsoftinternet_explorerMatch5.00.2919.6307
OR
microsoftinternet_explorerMatch5.00.2920.0000
OR
microsoftinternet_explorerMatch5.00.3103.1000
OR
microsoftinternet_explorerMatch5.00.3105.0106
OR
microsoftinternet_explorerMatch5.00.3314.2101
OR
microsoftinternet_explorerMatch5.00.3315.1000
OR
microsoftinternet_explorerMatch5.00.3502.1000
OR
microsoftinternet_explorerMatch5.00.3700.1000
OR
microsoftinternet_explorerMatch5.01
OR
microsoftinternet_explorerMatch5.1
OR
microsoftinternet_explorerMatch5.01sp1
OR
microsoftinternet_explorerMatch5.01sp2
OR
microsoftinternet_explorerMatch5.01sp3
OR
microsoftinternet_explorerMatch5.01sp4
OR
microsoftinternet_explorerMatch5.2.3
OR
microsoftinternet_explorerMatch5.5
OR
microsoftinternet_explorerMatch5.5preview
OR
microsoftinternet_explorerMatch5.5sp1
OR
microsoftinternet_explorerMatch5.5sp2
OR
microsoftinternet_explorerMatch5.50.3825.1300
OR
microsoftinternet_explorerMatch5.50.4030.2400
OR
microsoftinternet_explorerMatch5.50.4134.0100
OR
microsoftinternet_explorerMatch5.50.4134.0600
OR
microsoftinternet_explorerMatch5.50.4308.2900
OR
microsoftinternet_explorerMatch5.50.4522.1800
OR
microsoftinternet_explorerMatch5.50.4807.2300
OR
microsoftinternet_explorerMatch6
OR
microsoftinternet_explorerMatch6sp1
OR
microsoftinternet_explorerMatch6.0
OR
microsoftinternet_explorerMatch6.00.2462.0000
OR
microsoftinternet_explorerMatch6.00.2479.0006
OR
microsoftinternet_explorerMatch6.0.2600
OR
microsoftinternet_explorerMatch6.00.2600.0000
OR
microsoftinternet_explorerMatch6.0.2800
OR
microsoftinternet_explorerMatch6.0.2800.1106
OR
microsoftinternet_explorerMatch6.00.2800.1106
OR
microsoftinternet_explorerMatch6.0.2900
OR
microsoftinternet_explorerMatch6.0.2900.2180
OR
microsoftinternet_explorerMatch6.00.2900.2180
OR
microsoftinternet_explorerMatch6.00.3663.0000
OR
microsoftinternet_explorerMatch6.00.3718.0000
OR
microsoftinternet_explorerMatch6.00.3790.0000
OR
microsoftinternet_explorerMatch6.00.3790.1830
OR
microsoftinternet_explorerMatch6.00.3790.3959
OR
microsoftinternet_explorerMatch7
OR
microsoftinternet_explorerMatch7.0
OR
microsoftinternet_explorerMatch7.0beta
OR
microsoftinternet_explorerMatch7.0beta1
OR
microsoftinternet_explorerMatch7.0beta2
OR
microsoftinternet_explorerMatch7.0beta3
OR
microsoftinternet_explorerMatch7.0.5730unknowngold
OR
microsoftinternet_explorerMatch7.0.5730.11
OR
microsoftinternet_explorerMatch7.00.5730.1100
OR
microsoftinternet_explorerMatch7.00.6000.16386
OR
microsoftinternet_explorerMatch7.00.6000.16441
VendorProductVersionCPE
microsoftie9cpe:2.3:a:microsoft:ie:9:beta:*:*:*:*:*:*
microsoftinternet_explorer*cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*
microsoftinternet_explorer3.0cpe:2.3:a:microsoft:internet_explorer:3.0:*:*:*:*:*:*:*
microsoftinternet_explorer3.0.1cpe:2.3:a:microsoft:internet_explorer:3.0.1:*:*:*:*:*:*:*
microsoftinternet_explorer3.0.2cpe:2.3:a:microsoft:internet_explorer:3.0.2:*:*:*:*:*:*:*
microsoftinternet_explorer3.1cpe:2.3:a:microsoft:internet_explorer:3.1:*:*:*:*:*:*:*
microsoftinternet_explorer3.2cpe:2.3:a:microsoft:internet_explorer:3.2:*:*:*:*:*:*:*
microsoftinternet_explorer4.0cpe:2.3:a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*
microsoftinternet_explorer4.0.1cpe:2.3:a:microsoft:internet_explorer:4.0.1:*:*:*:*:*:*:*
microsoftinternet_explorer4.0.1cpe:2.3:a:microsoft:internet_explorer:4.0.1:sp1:*:*:*:*:*:*
Rows per page:
1-10 of 971

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.012

Percentile

85.4%

Related for NVD:CVE-2011-2382