Description
Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48815
Issue Tracking x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=380418
Scores
EPSS
0.1534
EPSS Percentile
96.4%
Details
CWE
CWE-264
Status
published
Products (1)
microsoft/xml_core_services
Published
Feb 04, 2009
Tracked Since
Feb 18, 2026