6.8
CVSSv2

CVE-2009-2064

Published: 15/06/2009 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle malicious users to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 6

microsoft pocket ie 1.1

microsoft pocket ie 2.0

microsoft internet explorer 8

microsoft internet explorer 8.0b

microsoft pocket ie 3.0

microsoft pocket ie 4.0

microsoft internet explorer 5

microsoft internet explorer 5.01

microsoft pocket ie 1.0

microsoft internet explorer

microsoft internet explorer 7

microsoft internet explorer 7.0.5730

microsoft pocket ie 2002

microsoft pocket ie 2003