Short Name |
HTTP:STC:IE:XSS-FILTER-DISC |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
HTTP |
Keywords |
Microsoft Internet Explorer Cross-Site Scripting Filter Information Disclosure |
Release Date |
2011/12/12 |
Update Number |
2046 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known flaw in Microsoft Internet Explorer. An attacker can create a web page that, when accessed by a victim, can allow the attacker to obtain data from another website the victim is also accessing. This could result in sensitive information disclosure.
Microsoft Internet Explorer is prone to a cross-domain information-disclosure vulnerability that affects the XSS Filter. An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content. Successful exploits will allow attackers to view potentially sensitive information from another domain or Internet Explorer zone; other attacks are possible.