|
|||
Rule General Information |
---|
Release Date: | 2010-03-09 | |
Rule Name: | WEB-CLIENT Microsoft Internet Explorer 7 Navigation Canceled Page cross site scripting -1 | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Microsoft Internet Explorer is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data. An attacker can exploit this issue to spoof the contents of the Navigation canceled page, steal cookie-based authentication credentials, and obtain other sensitive information. Successful exploits may assist in phishing or other attacks that rely on content spoofing. | |
Impact: | Remote code execution | |
Affected OS: | Windows | |
Reference: | SecurityFocusBID:22966 |
|
Solutions |
---|
Update vendor's patch. |