Back to search
CVE-2011-2382
Published: Jun 3, 2011
Modified: Sep 17, 2024
PUBLISHED
Description
Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://news.cnet.com/8301-1009_3-20066419-83.html
x_refsource_MISC
http://www.youtube.com/watch?v=VsSkcnIFCxM
x_refsource_MISC
http://www.networkworld.com/community/node/74259
x_refsource_MISC
http://www.youtube.com/watch?v=V95CX-3JpK0
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now