Vulnerabilities > CVE-2007-1114 - Unspecified vulnerability in Microsoft IE 7.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | OPERA_920.NASL |
description | The version of Opera installed on the remote host reportedly may allow a remote attacker to bypass cross-site scripting filters because it renders a web page without a defined charset with the charset of the parent page. In addition, its FTP implementation can be leveraged by remote attackers to force the client to connect to arbitrary servers via FTP PASV responses. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25036 |
published | 2007-04-14 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25036 |
title | Opera < 9.20 Multiple Vulnerabilities |
code |
|
References
- http://secunia.com/advisories/24314
- http://secunia.com/advisories/24314
- http://www.hardened-php.net/advisory_032007.142.html
- http://www.hardened-php.net/advisory_032007.142.html
- http://www.osvdb.org/32119
- http://www.osvdb.org/32119
- http://www.securityfocus.com/archive/1/461076/100/0/threaded
- http://www.securityfocus.com/archive/1/461076/100/0/threaded
- http://www.securityfocus.com/bid/22701
- http://www.securityfocus.com/bid/22701
- http://www.vupen.com/english/advisories/2007/0744
- http://www.vupen.com/english/advisories/2007/0744