Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN49467403/index.html | third party advisory |
http://www.us-cert.gov/cas/techalerts/TA10-089A.html | third party advisory us government resource |
http://www.securityfocus.com/bid/39028 | vdb entry patch |
http://www.us-cert.gov/cas/techalerts/TA10-068A.html | third party advisory us government resource |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-018 | vendor advisory |
http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000011.html | third party advisory |
http://www.vupen.com/english/advisories/2010/0744 | vdb entry patch vendor advisory |
http://securitytracker.com/id?1023773 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7840 | vdb entry signature |