Microsoft Internet Explorer 8 Cross-Site Scripting Filter Cross-Site Scripting Vulnerability
BID:37135
Info
Microsoft Internet Explorer 8 Cross-Site Scripting Filter Cross-Site Scripting Vulnerability
| Bugtraq ID: | 37135 |
| Class: | Design Error |
| CVE: |
CVE-2009-4074 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2009 12:00AM |
| Updated: | Apr 20 2010 06:53PM |
| Credit: | David Lindsay 'thornmaker' and Eduardo A. Vela Nava 'sirdarckcat' |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri CTI 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self Service - CDD 0 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Nortel Networks Media Processing Svr 100 0 Nortel Networks Media Processing Server Nortel Networks Contact Center Multimedia & Outbound 7.0 Nortel Networks Contact Center Multimedia & Outbound 6.0 Nortel Networks Contact Center Express Nortel Networks Contact Center Administration CCMA 7.0 Nortel Networks Contact Center Administration CCMA 6.0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 600r Nortel Networks CallPilot 202i Nortel Networks CallPilot 201i Nortel Networks CallPilot 1005r Microsoft Internet Explorer 8 RC1 Microsoft Internet Explorer 8 beta 2 Microsoft Internet Explorer 8 Beta 1 Microsoft Internet Explorer 8 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer 8 Cross-Site Scripting Filter Cross-Site Scripting Vulnerability
Microsoft Internet Explorer is prone to a cross-site scripting vulnerability because of a design flaw in the browser's cross-site scripting filter.
An attacker can exploit this issue to execute arbitrary script code in the context of the user running the application and to steal cookie-based authentication credentials and other sensitive data that may aid in further attacks.
Internet Explorer 8 is vulnerable.
Microsoft Internet Explorer is prone to a cross-site scripting vulnerability because of a design flaw in the browser's cross-site scripting filter.
An attacker can exploit this issue to execute arbitrary script code in the context of the user running the application and to steal cookie-based authentication credentials and other sensitive data that may aid in further attacks.
Internet Explorer 8 is vulnerable.
Exploit / POC
Microsoft Internet Explorer 8 Cross-Site Scripting Filter Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Microsoft Internet Explorer 8 Cross-Site Scripting Filter Cross-Site Scripting Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Internet Explorer 8
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Internet Explorer 8
-
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=7d480c87-2ca9 -4505-a59d-a6d73d001fa5 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=3e2e740b-8417 -4758-8468-15221249ec71 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=7c2948fb-f486 -4801-bc21-bbf40d5a78c2 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=41b83fad-948b -4a9c-80ed-9c5a60bd35b4 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=278443c1-15dc -436b-893b-ffea6d29d16d -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=a584cd0f-2e05 -4e36-8858-0ffead637162 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=f5ce8582-af63 -4870-bee3-0abeeefa1458 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Syste
http://www.microsoft.com/downloads/details.aspx?familyid=9d137bab-8312 -4240-af74-c65ba652fde0 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=d3386793-a594 -4bc5-8308-28b561d43087 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=be11981c-d286 -4e3c-94bf-d4e67a975d5a -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=5e2cbd7d-f64f -49e5-a159-1965ebfe2a92 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=b7a7e8e7-f4c5 -459d-ab6c-05a192e1e3f9
References
Microsoft Internet Explorer 8 Cross-Site Scripting Filter Cross-Site Scripting Vulnerability
References:
References:
- Abusing Internet Explorer 8's XSS Filters (David Lindsay & Eduardo Vela Nava)
- Avaya Enterprise (Fomerly Nortel Enterprise) Response to Microsoft Security Bull (Nortel Networks)
- ie8xss (David Lindsay & Eduardo Vela Nava)
- IE�??s XSS Filter Creates XSS Vulnerabilities (Giorgio)
- Major IE8 flaw makes 'safe' sites unsafe (The Register)
- Microsoft Internet Explorer Homepage (Microsoft)
- Universal XSS via IE8s XSS Filters (David Lindsay & Eduardo Vela Nava)
- Vulnerability Summary for CVE-2009-4074 (NIST)
- ASA-2010-018 MS10-002 Cumulative Security Update for Internet Explorer (978207) (Avaya)
- Microsoft Security Bulletin MS10-002 (Microsoft)