Show plain JSON{"cve": {"data_type": "CVE", "references": {"reference_data": [{"url": "https://sites.google.com/site/tentacoloviola/cookiejacking/Cookiejacking2011_final.ppt", "name": "https://sites.google.com/site/tentacoloviola/cookiejacking/Cookiejacking2011_final.ppt", "tags": [], "refsource": "MISC"}, {"url": "http://www.youtube.com/watch?v=VsSkcnIFCxM", "name": "http://www.youtube.com/watch?v=VsSkcnIFCxM", "tags": [], "refsource": "MISC"}, {"url": "http://conference.hackinthebox.org/hitbsecconf2011ams/?page_id=1388", "name": "http://conference.hackinthebox.org/hitbsecconf2011ams/?page_id=1388", "tags": [], "refsource": "MISC"}, {"url": "http://www.eweek.com/c/a/Security/IE-Flaw-Lets-Attackers-Steal-Cookies-Access-User-Accounts-402503/", "name": "http://www.eweek.com/c/a/Security/IE-Flaw-Lets-Attackers-Steal-Cookies-Access-User-Accounts-402503/", "tags": [], "refsource": "MISC"}, {"url": "http://www.youtube.com/watch?v=V95CX-3JpK0", "name": "http://www.youtube.com/watch?v=V95CX-3JpK0", "tags": [], "refsource": "MISC"}, {"url": "http://www.networkworld.com/community/node/74259", "name": "http://www.networkworld.com/community/node/74259", "tags": [], "refsource": "MISC"}, {"url": "http://news.cnet.com/8301-1009_3-20066419-83.html", "name": "http://news.cnet.com/8301-1009_3-20066419-83.html", "tags": [], "refsource": "MISC"}, {"url": "http://www.theregister.co.uk/2011/05/25/microsoft_internet_explorer_cookiejacking/", "name": "http://www.theregister.co.uk/2011/05/25/microsoft_internet_explorer_cookiejacking/", "tags": [], "refsource": "MISC"}, {"url": "http://ju12.tistory.com/attachment/cfile4.uf@151FAB4C4DDC9E0002A6FE.ppt", "name": "http://ju12.tistory.com/attachment/cfile4.uf@151FAB4C4DDC9E0002A6FE.ppt", "tags": [], "refsource": "MISC"}, {"url": "http://www.informationweek.com/news/security/vulnerabilities/229700031", "name": "http://www.informationweek.com/news/security/vulnerabilities/229700031", "tags": [], "refsource": "MISC"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12820", "name": "oval:org.mitre.oval:def:12820", "tags": [], "refsource": "OVAL"}, {"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-057", "name": "MS11-057", "tags": [], "refsource": "MS"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "en", "value": "Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: URL that redirects to a file: URL, as demonstrated by a Facebook game, related to a \"cookiejacking\" issue, aka \"Drag and Drop Information Disclosure Vulnerability.\" NOTE: this vulnerability exists because of an incomplete fix in the Internet Explorer 9 release."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "en", "value": "CWE-20"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2011-2383", "ASSIGNER": "cve@mitre.org"}}, "impact": {"baseMetricV2": {"cvssV2": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "severity": "MEDIUM", "impactScore": 2.9, "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}}, "publishedDate": "2011-06-03T17:55Z", "configurations": {"nodes": [{"children": [], "operator": "OR", "cpe_match": [{"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:5:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:3.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true, "versionEndIncluding": "9"}, {"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:microsoft:ie:9:beta:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}]}], "CVE_data_version": "4.0"}, "lastModifiedDate": "2021-07-23T15:12Z"}