7.1
CVSSv2

CVE-2009-1140

Published: 10/06/2009 Updated: 07/12/2023
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 715
Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote malicious users to bypass the Same Origin Policy via unspecified vectors, aka "Cross-Domain Information Disclosure Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet_explorer 6

microsoft internet_explorer 7

microsoft internet_explorer 5.01

Exploits

source: wwwsecurityfocuscom/bid/35200/info Microsoft Internet Explorer is prone to a cross-domain information-disclosure vulnerability because the application fails to properly enforce the same-origin policy An attacker can exploit this issue to access local files or content from a browser window in another domain or security zone This ...
Core Security Technologies Advisory - Internet Explorer suffers from a security zone restrictions bypass vulnerability ...