Internet Explorer 8 CSS 'expression' Property Cross Site Scripting Filter Bypass Weakness
BID:32780
Info
Internet Explorer 8 CSS 'expression' Property Cross Site Scripting Filter Bypass Weakness
| Bugtraq ID: | 32780 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2008 12:00AM |
| Updated: | Dec 12 2008 04:21AM |
| Credit: | Rafel Ivgi |
| Vulnerable: |
Microsoft Internet Explorer 8 beta 2 |
| Not Vulnerable: | |
Discussion
Internet Explorer 8 CSS 'expression' Property Cross Site Scripting Filter Bypass Weakness
Microsoft Internet Explorer is a web browser for the Microsoft Windows operating system.
Internet Explorer 8 includes a cross-site-scripting filter that is designed to prevent cross-site-scripting attacks against vulnerable web applications. Attackers may be able to bypass this filter under certain conditions, such as by taking advantage of an existing vulnerability in a web application.
Internet Explorer 8 beta 2 is vulnerable.
Microsoft Internet Explorer is a web browser for the Microsoft Windows operating system.
Internet Explorer 8 includes a cross-site-scripting filter that is designed to prevent cross-site-scripting attacks against vulnerable web applications. Attackers may be able to bypass this filter under certain conditions, such as by taking advantage of an existing vulnerability in a web application.
Internet Explorer 8 beta 2 is vulnerable.
Exploit / POC
Internet Explorer 8 CSS 'expression' Property Cross Site Scripting Filter Bypass Weakness
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example parameter is available:
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example parameter is available:
Solution / Fix
Internet Explorer 8 CSS 'expression' Property Cross Site Scripting Filter Bypass Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Internet Explorer 8 CSS 'expression' Property Cross Site Scripting Filter Bypass Weakness
References:
References:
- Internet Explorer 8 Beta Webpage (Microsoft)
- Aspect9: Internet Explorer 8.0 Beta 2 Anti-XSS Filter Vulnerabilities ("Rafel Ivgi"
)