Microsoft Internet Explorer Incomplete Fix CVE-2008-3173 Session Hijacking Vulnerability
BID:69333
Info
Microsoft Internet Explorer Incomplete Fix CVE-2008-3173 Session Hijacking Vulnerability
| Bugtraq ID: | 69333 |
| Class: | Design Error |
| CVE: |
CVE-2008-3173 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 22 2008 12:00AM |
| Updated: | Feb 22 2008 12:00AM |
| Credit: | crisp |
| Vulnerable: |
Microsoft Microsoft Internet Explorer 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Incomplete Fix CVE-2008-3173 Session Hijacking Vulnerability
Microsoft Internet Explorer is prone to a session-hijacking vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
Note: This issue exists due to an incomplete fix for CVE-2004-0866 (identified in BID 11186- Multiple Browser Cross-Domain Cookie Injection Vulnerability).
Microsoft Internet Explorer is prone to a session-hijacking vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
Note: This issue exists due to an incomplete fix for CVE-2004-0866 (identified in BID 11186- Multiple Browser Cross-Domain Cookie Injection Vulnerability).
Exploit / POC
Microsoft Internet Explorer Incomplete Fix CVE-2008-3173 Session Hijacking Vulnerability
Attackers can exploit this issue with a web browser.
Attackers can exploit this issue with a web browser.
References
Microsoft Internet Explorer Incomplete Fix CVE-2008-3173 Session Hijacking Vulnerability
References:
References:
- IE and 2-letter domain-names (crisp)
- Internet Explorer Homepage (Microsoft)
- Microsoft Internet Explorer cookie dot session hijacking (IBM)