Vulnerability CVE-2008-4033


Published: 2008-11-12   Modified: 2012-02-12

Description:
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."

Type:

CWE-200

(Information Exposure)

Vendor: Microsoft
Product: 20007 office system 
Version: sp1;
Product: Xml core services 
Version:
6.0
5.0
4.0
3.0
Product: Office sharepoint server 
Version: 2007;
Product: Office groove server 
Version: 2007;
Product: Office 
Version: 2003;
Product: Word viewer 
Version: 2003;
Product: Expression web 
Version: 2;
Product: Office compatibility pack for word excel ppt 2007 

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
http://marc.info/?l=bugtraq&m=122703006921213&w=2
http://securitytracker.com/id?1021164
http://www.securityfocus.com/bid/32204
http://www.us-cert.gov/cas/techalerts/TA08-316A.html
http://www.vupen.com/english/advisories/2008/3111
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-069
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5847

Related CVE
CVE-2019-0879
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0...
CVE-2019-0877
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0...
CVE-2019-0876
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.
CVE-2019-0875
An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions, aka 'Azure DevOps Server Elevation of Privilege Vulnerability'.
CVE-2019-0874
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
CVE-2019-0871
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID i...
CVE-2019-0870
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID i...
CVE-2019-0869
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.

Copyright 2019, cxsecurity.com

 

Back to Top