Short Name |
HTTP:STC:IE:CHAN-SCRIPT |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
HTTP |
Keywords |
Script in CHANNEL Tag |
Release Date |
2005/02/07 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit the cross-domain vulnerability in Microsoft Internet Explorer. Attackers can create a malicious Web page that, when viewed by a user subscribed to an MSN channel, enables them to obtain information, remotely execute arbitrary code, or take complete control of the target system.
A vulnerability has been reported in Microsoft Internet Explorer that could enable unauthorized access by malicious scripts and Active Content to document properties across different Security Zones and foreign domains. This issue is exposed when a remote site uses the 'AddChannel' method to add a channel. Exploitation of this issue could allow various attacks, such as cookie-theft from an arbitrary domain. Other issues may also facilitate execution of arbitrary code on a vulnerable client system by causing malicious content to be stored on the victim system and then referenced.