CVE-2009-4074

The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability."
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*

History

21 Nov 2024, 01:08

Type Values Removed Values Added
References () http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/ - () http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/ -
References () http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf - () http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf -
References () http://www.securityfocus.com/bid/37135 - () http://www.securityfocus.com/bid/37135 -
References () http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/ - () http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/ -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7715 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7715 -

Information

Published : 2009-11-25 18:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-4074

Mitre link : CVE-2009-4074

CVE.ORG link : CVE-2009-4074


JSON object : View

Products Affected

microsoft

  • internet_explorer