Microsoft Internet Explorer 'Print Table of Links' Cross Zone Script Injection Vulnerability
BID:29217
Info
Microsoft Internet Explorer 'Print Table of Links' Cross Zone Script Injection Vulnerability
| Bugtraq ID: | 29217 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2281 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Aviv Raff |
| Vulnerable: |
Microsoft Internet Explorer 8 Beta 1 Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer 'Print Table of Links' Cross Zone Script Injection Vulnerability
Microsoft Internet Explorer is prone to a script-injection vulnerability because it fails to adequately sanitize user-supplied input when printing a table of links.
Attackers can exploit this issue by enticing an unsuspecting user to initiate the printing procedure while viewing a specially crafted page. Successful exploits will cause malicious script code to run in the 'Local Machine Zone' of a victim's computer.
Internet Explorer 7.0 and 8.0b are vulnerable; other versions may also be affected.
Reports indicate that successful exploits on Windows Vista platforms running UAC can cause only information disclosure.
Microsoft Internet Explorer is prone to a script-injection vulnerability because it fails to adequately sanitize user-supplied input when printing a table of links.
Attackers can exploit this issue by enticing an unsuspecting user to initiate the printing procedure while viewing a specially crafted page. Successful exploits will cause malicious script code to run in the 'Local Machine Zone' of a victim's computer.
Internet Explorer 7.0 and 8.0b are vulnerable; other versions may also be affected.
Reports indicate that successful exploits on Windows Vista platforms running UAC can cause only information disclosure.
Exploit / POC
Microsoft Internet Explorer 'Print Table of Links' Cross Zone Script Injection Vulnerability
To exploit this issue an attacker must entice an unsuspecting user to open a malicious page and to perform a certain printing function on it.
The following example exploit is available:
To exploit this issue an attacker must entice an unsuspecting user to open a malicious page and to perform a certain printing function on it.
The following example exploit is available:
Solution / Fix
Microsoft Internet Explorer 'Print Table of Links' Cross Zone Script Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer 'Print Table of Links' Cross Zone Script Injection Vulnerability
References:
References: