he MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded content in an HTML document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted EMBED element in a web page that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
Configuration 1 (hide)
|
21 Nov 2024, 01:27
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.securityfocus.com/bid/48205 - | |
| References | () http://www.securitytracker.com/id?1025655 - | |
| References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-037 - | |
| References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12494 - |
Published : 2011-06-16 20:55
Updated : 2025-04-11 00:51
NVD link : CVE-2011-1894
Mitre link : CVE-2011-1894
CVE.ORG link : CVE-2011-1894
JSON object : View
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')