Vulnerabilities > CVE-2008-2281 - Unspecified vulnerability in Microsoft IE and Internet Explorer

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
microsoft
critical
exploit available

Summary

Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document.

Vulnerable Configurations

Part Description Count
Application
Microsoft
3

Exploit-Db

descriptionMS Internet Explorer (Print Table of Links) Cross-Zone Scripting PoC. CVE-2008-2281. Remote exploit for windows platform
fileexploits/windows/remote/5619.html
idEDB-ID:5619
last seen2016-01-31
modified2008-05-14
platformwindows
port
published2008-05-14
reporterAviv Raff
sourcehttps://www.exploit-db.com/download/5619/
titleMicrosoft Internet Explorer Print Table of Links Cross-Zone Scripting PoC
typeremote