← All CVEs

CVE-2005-4089

high · 7.1

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."

7.1
CVSS
22.1%
EPSS (exploit prob.)
98th
EPSS percentile
2005-12-08
Published

AV:N/AC:M/Au:N/C:C/I:N/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
microsoftie6.0
microsoftie6.0
microsoftinternet_explorer6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-4089