PT-2007-4742 · Microsoft · Internet Explorer

CVE-2007-3481

·

Published

2007-06-28

·

Updated

2024-08-07

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 6 through 7
Description A cross-domain issue allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript. This is achieved by overwriting the document variable and statically setting the document.domain attribute. The issue has been disputed by other researchers, who cite a variable scoping issue and information about the semantics of document.domain.
Recommendations For Microsoft Internet Explorer versions 6 and 7, as a temporary workaround, consider restricting the use of JavaScript that overwrites the document variable and sets the document.domain attribute until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-3481

Affected Products

Internet Explorer