vendor:
Internet Explorer
by:
Andreas Sandblad
7.5
CVSS
HIGH
Cross-Zone Policy Violation
16
CWE
Product Name: Internet Explorer
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2004
Microsoft Internet Explorer Cross-Zone Policy Violation
It has been reported that the issue presents itself due to a failure by Internet Explorer to remove JavaScript URIs from the browser history list in some circumstances. A JavaScript specific JavaScript URI, can be embedded in the Browser history list and further employed by an attacker to have JavaScript code executed in the context of the Local Machine security zone.
Mitigation:
Microsoft released a patch for this vulnerability in 2004 (MS04-004).