CVE-2009-2350
medium · 4.3Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312.
4.3
CVSS
14.4%
EPSS (exploit prob.)
96th
EPSS percentile
2009-07-07
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_explorer | 6 |
Check a specific version with /api/v1/cve/match.
References
- http://websecurity.com.ua/3275/
- http://websecurity.com.ua/3386/
- http://www.securityfocus.com/archive/1/504718/100/0/threaded
- http://www.securityfocus.com/archive/1/504723/100/0/threaded
- http://www.securityfocus.com/bid/35570
- http://websecurity.com.ua/3275/
- http://websecurity.com.ua/3386/
- http://www.securityfocus.com/archive/1/504718/100/0/threaded
- http://www.securityfocus.com/archive/1/504723/100/0/threaded
- http://www.securityfocus.com/bid/35570
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-2350