Microsoft Internet Explorer 'DisableCachingOfSSLPages' Security Weakness
BID:29120
Info
Microsoft Internet Explorer 'DisableCachingOfSSLPages' Security Weakness
| Bugtraq ID: | 29120 |
| Class: | Design Error |
| CVE: |
CVE-2008-2159 |
| Remote: | No |
| Local: | Yes |
| Published: | May 09 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Bill KNox |
| Vulnerable: |
Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer 'DisableCachingOfSSLPages' Security Weakness
Microsoft Internet Explorer is prone to a weakness that may allow attackers to extract potentially sensitive information.
Attackers with local access to a computer may exploit this issue to obtain potentially sensitive information from cached SSL-enabled web pages. Information obtained may aid in further attacks.
This issue affects Internet Explorer 7.
Microsoft Internet Explorer is prone to a weakness that may allow attackers to extract potentially sensitive information.
Attackers with local access to a computer may exploit this issue to obtain potentially sensitive information from cached SSL-enabled web pages. Information obtained may aid in further attacks.
This issue affects Internet Explorer 7.
Exploit / POC
Microsoft Internet Explorer 'DisableCachingOfSSLPages' Security Weakness
Attackers can exploit this issue using standard tools.
Attackers can exploit this issue using standard tools.
Solution / Fix
Microsoft Internet Explorer 'DisableCachingOfSSLPages' Security Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer 'DisableCachingOfSSLPages' Security Weakness
References:
References: