vendor:
Internet Explorer
by:
Christian Haider
5.5
CVSS
MEDIUM
Cookie theft
200
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 8
Affected Version To: Internet Explorer 9
Patch Exists: NO
Related CWE: CVE-2013-1451
CPE: a:microsoft:internet_explorer:8, cpe:/a:microsoft:internet_explorer:9
Platforms Tested: Windows 7, Windows XP
2013
Internet Explorer 8 & Internet Explorer 9 steal any Cookie
This vulnerability allows an attacker to steal cookies from Internet Explorer 8 and 9. The attacker needs to use the same proxy for HTTP and HTTPS. The risk can be mitigated by changing the configuration. The vulnerability has not been rated as high risk by Microsoft.
Mitigation:
Change the configuration to use different proxies for HTTP and HTTPS.