CVE-2008-2948
Microsoft Internet Explorer 7-8 - XSS
Title source: llmDescription
Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.
Exploits (1)
References (7)
Scores
EPSS
0.4394
EPSS Percentile
97.5%
Details
Status
published
Products (2)
microsoft/internet_explorer
7
microsoft/internet_explorer
8
Published
Jun 30, 2008
Tracked Since
Feb 18, 2026