PT-2010-2537 · Microsoft · Internet Explorer
Published
2010-10-13
·
Updated
2023-12-07
·
CVE-2010-0808
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 6 through 7
Description
The issue allows remote attackers to obtain sensitive form information via a crafted web site by simulating user interaction with the AutoComplete feature. An attacker could exploit this by constructing a specially crafted Web page, potentially capturing information previously entered into fields after the AutoComplete feature has been enabled.
Recommendations
For Microsoft Internet Explorer versions 6 through 7, consider disabling the AutoComplete feature as a temporary workaround until a patch is available. Restrict access to sensitive form information to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer