Unknown
CVE-2011-2382
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a “cookiejacking” issue.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- ie 9,
- internet explorer,
- internet explorer 3.0,
- internet explorer 3.0.1,
- internet explorer 3.0.2,
- internet explorer 3.1,
- internet explorer 3.2,
- internet explorer 4.0,
- internet explorer 4.0.1,
- internet explorer 4.01,
- internet explorer 4.1,
- internet explorer 4.40.308,
- internet explorer 4.40.520,
- internet explorer 4.5,
- internet explorer 4.70.1155,
- internet explorer 4.70.1158,
- internet explorer 4.70.1215,
- internet explorer 4.70.1300,
- internet explorer 4.71.1008.3,
- internet explorer 4.71.1712.6,
- internet explorer 4.71.544,
- internet explorer 4.72.2106.8,
- internet explorer 4.72.3110.8,
- internet explorer 4.72.3612.1713,
- internet explorer 5,
- internet explorer 5.0,
- internet explorer 5.0.1,
- internet explorer 5.00.0518.10,
- internet explorer 5.00.0910.1309,
- internet explorer 5.00.2014.0216,
- internet explorer 5.00.2314.1003,
- internet explorer 5.00.2516.1900,
- internet explorer 5.00.2614.3500,
- internet explorer 5.00.2919.3800,
- internet explorer 5.00.2919.6307,
- internet explorer 5.00.2919.800,
- internet explorer 5.00.2920.0000,
- internet explorer 5.00.3103.1000,
- internet explorer 5.00.3105.0106,
- internet explorer 5.00.3314.2101,
- internet explorer 5.00.3315.1000,
- internet explorer 5.00.3502.1000,
- internet explorer 5.00.3700.1000,
- internet explorer 5.01,
- internet explorer 5.1,
- internet explorer 5.2.3,
- internet explorer 5.5,
- internet explorer 5.50.3825.1300,
- internet explorer 5.50.4030.2400,
- internet explorer 5.50.4134.0100,
- internet explorer 5.50.4134.0600,
- internet explorer 5.50.4308.2900,
- internet explorer 5.50.4522.1800,
- internet explorer 5.50.4807.2300,
- internet explorer 6,
- internet explorer 6.0,
- internet explorer 6.0.2600,
- internet explorer 6.0.2800,
- internet explorer 6.0.2800.1106,
- internet explorer 6.0.2900,
- internet explorer 6.0.2900.2180,
- internet explorer 6.00.2462.0000,
- internet explorer 6.00.2479.0006,
- internet explorer 6.00.2600.0000,
- internet explorer 6.00.2800.1106,
- internet explorer 6.00.2900.2180,
- internet explorer 6.00.3663.0000,
- internet explorer 6.00.3718.0000,
- internet explorer 6.00.3790.0000,
- internet explorer 6.00.3790.1830,
- internet explorer 6.00.3790.3959,
- internet explorer 7,
- internet explorer 7.0,
- internet explorer 7.0.5730,
- internet explorer 7.0.5730.11,
- internet explorer 7.00.5730.1100,
- internet explorer 7.00.6000.16386,
- internet explorer 7.00.6000.16441
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: