CVE-2010-1489

Microsoft Internet Explorer 8 - XSS

Title source: llm

Description

The XSS Filter in Microsoft Internet Explorer 8 does not properly perform neutering for the SCRIPT tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, a different issue than CVE-2009-4074.

Scores

EPSS 0.2205
EPSS Percentile 95.7%

Classification

CWE
CWE-79
Status published

Affected Products (2)

microsoft/internet_explorer
n/a/n/a

Timeline

Published Apr 20, 2010
Tracked Since Feb 18, 2026