Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-12-08 03:03
Updated : 2021-07-23 05:55
NVD link : CVE-2005-4089
Mitre link : CVE-2005-4089
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
microsoft
- internet_explorer
- ie