vendor:
Internet Explorer
by:
Unknown
N/A
CVSS
N/A
Security Bypass
Unknown
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 8
Affected Version To: Internet Explorer 8
Patch Exists: Unknown
Related CWE: Unknown
CPE: a:microsoft:internet_explorer:8
Platforms Tested: Windows
Unknown
Internet Explorer 8 Security Bypass Weakness
Internet Explorer 8 includes a method designed to sanitize executable script constructs from HTML. Attackers can bypass this protection, allowing script code to execute on the client, for example in a 'postMessage' call. Attackers can leverage this issue to obtain sensitive information or potentially launch cross-site scripting attacks on unsuspecting users of targeted sites. Other attacks may also be possible.
Mitigation:
Unknown