CVE-2008-7295

Microsoft Internet Explorer - Info Disclosure

Title source: llm
STIX 2.1

Description

Microsoft Internet Explorer cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

Scores

EPSS 0.0510
EPSS Percentile 91.4%

Details

CWE
CWE-264
Status published
Products (1)
microsoft/internet_explorer
Published Aug 09, 2011
Tracked Since Feb 18, 2026