Multiple Web Browser UTF-7 Cross-Domain Character-Set-Inheritance Vulnerability
BID:22701
Info
Multiple Web Browser UTF-7 Cross-Domain Character-Set-Inheritance Vulnerability
| Bugtraq ID: | 22701 |
| Class: | Design Error |
| CVE: |
CVE-2007-1115 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2007 12:00AM |
| Updated: | Apr 30 2007 04:30PM |
| Credit: | Stefan Esser is credited with the discovery of this issue. |
| Vulnerable: |
SuSE Linux 9.3 x86-64 SuSE Linux 9.3 x86 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. openSUSE 10.2 Opera Software Opera Web Browser 9.10 Opera Software Opera Web Browser 9.02 Opera Software Opera Web Browser 9.01 Opera Software Opera Web Browser 9 Microsoft Internet Explorer 7.0 beta3 Microsoft Internet Explorer 7.0 beta2 Microsoft Internet Explorer 7.0 beta1 Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Multiple Web Browser UTF-7 Cross-Domain Character-Set-Inheritance Vulnerability
Opera Web Browser and Microsoft Internet Explorer are prone to a cross-domain character-set-inheritance vulnerability.
Exploiting this issue can allow attackers to perform cross-site scripting attacks on unsuspecting users. If successful, attackers can steal cookie-based authentication credentials.
Opera Web Browser 9 series and Microsoft Internet Explorer 7 series are affected.
Opera Web Browser and Microsoft Internet Explorer are prone to a cross-domain character-set-inheritance vulnerability.
Exploiting this issue can allow attackers to perform cross-site scripting attacks on unsuspecting users. If successful, attackers can steal cookie-based authentication credentials.
Opera Web Browser 9 series and Microsoft Internet Explorer 7 series are affected.
Exploit / POC
Multiple Web Browser UTF-7 Cross-Domain Character-Set-Inheritance Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI hosted on a malicious page.
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI hosted on a malicious page.