HTTP: Microsoft Internet Explorer Cross-Site Scripting Filter Information Disclosure

This signature detects attempts to exploit a known flaw in Microsoft Internet Explorer. An attacker can create a web page that, when accessed by a victim, can allow the attacker to obtain data from another website the victim is also accessing. This could result in sensitive information disclosure.

Extended Description

Microsoft Internet Explorer is prone to a cross-domain information-disclosure vulnerability that affects the XSS Filter. An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content. Successful exploits will allow attackers to view potentially sensitive information from another domain or Internet Explorer zone; other attacks are possible.

Affected Products

Avaya messaging_application_server,Avaya meeting_exchange

References

BugTraq: 50974

CVE: CVE-2011-1992

Short Name
HTTP:STC:IE:XSS-FILTER-DISC
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2011-1992 Cross-Site Disclosure Explorer Filter Information Internet Microsoft Scripting bid:50974
Release Date
12/13/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Avaya

Microsoft

CVSS Score

4.3

Found a potential security threat?