CVE-2008-5551
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 13.99% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/4724
- http://www.securityfocus.com/archive/1/499124/100/0/threaded
- http://www.securityfocus.com/bid/32780Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47277
- http://securityreason.com/securityalert/4724
- http://www.securityfocus.com/archive/1/499124/100/0/threaded
- http://www.securityfocus.com/bid/32780Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47277
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.