Description
The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability."
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7715
Various Sources x_refsource_misc
http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/
Various Sources x_refsource_misc
http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/
Various Sources x_refsource_misc
http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/37135
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002
Scores
EPSS
0.1484
EPSS Percentile
96.4%
Details
Status
published
Products (1)
microsoft/internet_explorer
8
Published
Nov 25, 2009
Tracked Since
Feb 18, 2026