CVE-2011-1244UI Misrepresentation / Clickjacking in Microsoft Internet Explorer

Severity
5.8MEDIUMNVD
EPSS
6.9%
top 8.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 13
Latest updateMay 13

Description

Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content access, which allows remote attackers to obtain sensitive information or conduct clickjacking attacks via a crafted web site, aka "Frame Tag Information Disclosure Vulnerability."

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-jxjh-hj3p-4x88: Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content access, which allows remote attackers to obtain sensi2022-05-13
CVE-2011-1244 — UI Misrepresentation / Clickjacking | cvebase