Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vectors, aka "Event Handler Cross-Domain Vulnerability."
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11954 | vdb entry signature |
http://www.us-cert.gov/cas/techalerts/TA10-222A.html | third party advisory us government resource |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-053 | vendor advisory |