Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Information Disclosure Vulnerability
BID:33803
Info
Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Information Disclosure Vulnerability
| Bugtraq ID: | 33803 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2009-0419 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2009 12:00AM |
| Updated: | Feb 17 2009 11:08PM |
| Credit: | Wladimir Palant |
| Vulnerable: |
Microsoft XML Core Services 6.0 Microsoft XML Core Services 5.0 Microsoft XML Core Services 4.0 Microsoft XML Core Services 3.0 |
| Not Vulnerable: | |
Discussion
Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Information Disclosure Vulnerability
Microsoft XML Core Services (MSXML) is prone to an information-disclosure vulnerability because it fails to properly protect sensitive cookie data with the 'HTTPOnly' protection mechanism.
A successful exploit may allow attackers to steal cookie-based authentication credentials; information harvested may aid in further attacks.
Microsoft XML Core Services (MSXML) is prone to an information-disclosure vulnerability because it fails to properly protect sensitive cookie data with the 'HTTPOnly' protection mechanism.
A successful exploit may allow attackers to steal cookie-based authentication credentials; information harvested may aid in further attacks.
Exploit / POC
Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Information Disclosure Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
Solution / Fix
Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Information Disclosure Vulnerability
References:
References:
- Bugzilla Bug 380418: (CVE-2009-0357) XMLHttpRequest allows reading HTTPOnly cook (Wladimir Palant)
- Microsoft XML Resource Site (Microsoft)