Headline
CVE-2011-3404: Oval Repository
Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka “Content-Disposition Information Disclosure Vulnerability.”
New Search
Content-Disposition Information Disclosure Vulnerability****oval:org.mitre.oval:def:14614
Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site aka “Content-Disposition Information Disclosure Vulnerability.”
Platform(s):
- Microsoft Windows Server 2008
- Microsoft Windows XP
- Microsoft Windows 7
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2003
- Microsoft Windows Vista
Reference(s):
- CVE-2011-3404
Product(s):
- Microsoft Internet Explorer 9
- Microsoft Internet Explorer 7
- Microsoft Internet Explorer 6
- Microsoft Internet Explorer 8