CVE-2011-1258

Microsoft Internet Explorer 6-8 - Information Disclosure via Drag-and-Drop Operation

Title source: llm
STIX 2.1

Description

Microsoft Internet Explorer 6 through 8 does not properly restrict web script, which allows user-assisted remote attackers to obtain sensitive information from a different (1) domain or (2) zone via vectors involving a drag-and-drop operation, aka "Drag and Drop Information Disclosure Vulnerability."

Scores

EPSS 0.1465
EPSS Percentile 96.2%

Details

CWE
CWE-668
Status published
Products (3)
microsoft/internet_explorer 6
microsoft/internet_explorer 7
microsoft/internet_explorer 8
Published Jun 16, 2011
Tracked Since Feb 18, 2026