Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Windows DHTML Edit Control Script Injection Vulnerability

Microsoft Windows DHTML Edit control may be used to carry out cross-domain script injection through Internet Explorer. This issue may allow an attacker to execute malicious script code in a user's browser to facilitate cross-site scripting attacks.

An attacker may be able to steal cookie-based authentication credentials through this vulnerability. Other attacks may be possible as well.

Note: This issue was originally documented as an Internet Explorer vulnerability. Microsoft has reported that this vulnerability is an operating system issue and has released appropriate operating system fixes.







 

Privacy Statement
Copyright 2008, SecurityFocus