CVE-2011-2382
medium · 4.3Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.
4.3
CVSS
19.3%
EPSS (exploit prob.)
97th
EPSS percentile
2011-06-03
Published
AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | ie | 9 |
| microsoft | internet_explorer | <= 8 |
| microsoft | internet_explorer | 3.0 |
| microsoft | internet_explorer | 3.0.1 |
| microsoft | internet_explorer | 3.0.2 |
| microsoft | internet_explorer | 3.1 |
| microsoft | internet_explorer | 3.2 |
| microsoft | internet_explorer | 4.0 |
| microsoft | internet_explorer | 4.0.1 |
| microsoft | internet_explorer | 4.0.1 |
| microsoft | internet_explorer | 4.0.1 |
| microsoft | internet_explorer | 4.01 |
| microsoft | internet_explorer | 4.1 |
| microsoft | internet_explorer | 4.01 |
| microsoft | internet_explorer | 4.5 |
| microsoft | internet_explorer | 4.40.308 |
| microsoft | internet_explorer | 4.40.520 |
| microsoft | internet_explorer | 4.70.1155 |
| microsoft | internet_explorer | 4.70.1158 |
| microsoft | internet_explorer | 4.70.1215 |
| microsoft | internet_explorer | 4.70.1300 |
| microsoft | internet_explorer | 4.71.544 |
| microsoft | internet_explorer | 4.71.1008.3 |
| microsoft | internet_explorer | 4.71.1712.6 |
| microsoft | internet_explorer | 4.72.2106.8 |
| microsoft | internet_explorer | 4.72.3110.8 |
| microsoft | internet_explorer | 4.72.3612.1713 |
| microsoft | internet_explorer | 5 |
| microsoft | internet_explorer | 5.0 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.0.1 |
| microsoft | internet_explorer | 5.00.0518.10 |
| microsoft | internet_explorer | 5.00.0910.1309 |
| microsoft | internet_explorer | 5.00.2014.0216 |
| microsoft | internet_explorer | 5.00.2314.1003 |
| microsoft | internet_explorer | 5.00.2516.1900 |
| microsoft | internet_explorer | 5.00.2614.3500 |
Check a specific version with /api/v1/cve/match.
References
- http://conference.hackinthebox.org/hitbsecconf2011ams/?page_id=1388
- http://ju12.tistory.com/attachment/cfile4.uf%40151FAB4C4DDC9E0002A6FE.ppt
- http://news.cnet.com/8301-1009_3-20066419-83.html
- http://www.eweek.com/c/a/Security/IE-Flaw-Lets-Attackers-Steal-Cookies-Access-User-Accounts-402503/
- http://www.informationweek.com/news/security/vulnerabilities/229700031
- http://www.networkworld.com/community/node/74259
- http://www.theregister.co.uk/2011/05/25/microsoft_internet_explorer_cookiejacking/
- http://www.youtube.com/watch?v=V95CX-3JpK0
- http://www.youtube.com/watch?v=VsSkcnIFCxM
- https://sites.google.com/site/tentacoloviola/cookiejacking/Cookiejacking2011_final.ppt
- http://conference.hackinthebox.org/hitbsecconf2011ams/?page_id=1388
- http://ju12.tistory.com/attachment/cfile4.uf%40151FAB4C4DDC9E0002A6FE.ppt
- http://news.cnet.com/8301-1009_3-20066419-83.html
- http://www.eweek.com/c/a/Security/IE-Flaw-Lets-Attackers-Steal-Cookies-Access-User-Accounts-402503/
- http://www.informationweek.com/news/security/vulnerabilities/229700031
- http://www.networkworld.com/community/node/74259
- http://www.theregister.co.uk/2011/05/25/microsoft_internet_explorer_cookiejacking/
- http://www.youtube.com/watch?v=V95CX-3JpK0
- http://www.youtube.com/watch?v=VsSkcnIFCxM
- https://sites.google.com/site/tentacoloviola/cookiejacking/Cookiejacking2011_final.ppt
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-2382