PT-2010-2249 · Microsoft · Internet Explorer

Daiki Fukumori

·

Published

2010-03-31

·

Updated

2025-01-21

·

CVE-2010-0488

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 5.01 SP4, 6, 6 SP1, and 7
Description The issue allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. An information disclosure vulnerability exists in the way that Internet Explorer handles content using specific encoding strings when submitting data. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow information disclosure if a user viewed the Web page. This could allow an attacker to view content from the local computer or another browser window in another domain or Internet Explorer zone.
Recommendations For Microsoft Internet Explorer versions 5.01 SP4, 6, 6 SP1, and 7, consider restricting access to sensitive information and avoiding the use of specific encoding strings when submitting data as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2010-0488

Affected Products

Internet Explorer