CVE Vulnerabilities

CVE-2005-4089

Published: Dec 08, 2005 | Modified: Jul 23, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka CSSXSS and CSS Cross-Domain Information Disclosure Vulnerability.

Affected Software

Name Vendor Start Version End Version
Ie Microsoft 6.0-sp1 (including) 6.0-sp1 (including)
Ie Microsoft 6.0-sp2 (including) 6.0-sp2 (including)
Internet_explorer Microsoft 6.0 (including) 6.0 (including)

References