blogs.technet.comConfirmation
http://blogs.technet.com/b/msrc/archive/2011/01/28/microsoft-releases-security-advisory-2501696.aspx CVE-2011-0096
MEDIUM
Microsoft Windows Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2011-0096 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 12, 2011 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WindowsBrowse Microsoft / Windows | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Internet Explorer - MHTML Protocol Handler Cross-Site ScriptingExploitDB exploitby 80vulNot analyzed1 file
References
Showing 12 of 16blogs.technet.comConfirmation
http://blogs.technet.com/b/srd/archive/2011/01/28/more-information-about-the-mhtml-script-injection-vulnerability.aspx 70693vdb entry
http://osvdb.org/70693 43093Third-party advisory
http://secunia.com/advisories/43093 80vul.com
http://www.80vul.com/webzine_0x05/0x05%20IE%E4%B8%8BMHTML%E5%8D%8F%E8%AE%AE%E5%B8%A6%E6%9D%A5%E7%9A%84%E8%B7%A8%E5%9F%9F%E5%8D%B1%E5%AE%B3.html 16071exploit
http://www.exploit-db.com/exploits/16071 VU#326549Third-party advisory
http://www.kb.cert.org/vuls/id/326549 microsoft.comConfirmation
http://www.microsoft.com/technet/security/advisory/2501696.mspx 46055vdb entry
http://www.securityfocus.com/bid/46055 1025003vdb entry
http://www.securitytracker.com/id?1025003 TA11-102AThird-party advisory
http://www.us-cert.gov/cas/techalerts/TA11-102A.html ADV-2011-0242vdb entry
http://www.vupen.com/english/advisories/2011/0242