First published: Thu Dec 08 2005(Updated: )
Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 | |
Microsoft Internet Explorer | =6.0-sp2 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4089 is considered a moderate severity vulnerability due to its ability to bypass security restrictions in Microsoft Internet Explorer.
To fix CVE-2005-4089, users should upgrade to a patched version of Microsoft Internet Explorer or apply available security updates.
CVE-2005-4089 affects Internet Explorer version 6.0 with Service Pack 1 and 2.
CVE-2005-4089 is a cross-domain security vulnerability that allows unauthorized access to sensitive information.
Yes, CVE-2005-4089 can be exploited remotely by attackers to obtain sensitive information.