RULE(RULE ID:322453)

Rule General Information
Release Date: 2019-07-06
Rule Name: Internet Explorer - Cross Domain Cookie Theft Vulnerability (CVE-2008-3472)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "HTML Element Cross-Domain Vulnerability."
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:31615
SecurityTrackerID:1021047
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-058
http://marc.info/?l=bugtraq&m=122479227205998&w=2
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-058