CVE-2010-0488

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."
Severity
UNKNOWN
AV:N/AC:M/Au:N/C:P/I:N/A:N
Atk. Vector
NETWORK
Atk. Complexity
MEDIUM
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
microsoftwindows_2003_server
*
microsoftwindows_server_2003
*
microsoftwindows_xp
*
microsoftwindows_xp
*
microsoftwindows_xp
-
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_2003_server
*
microsoftwindows_2003_server
*
microsoftwindows_server_2003
*
microsoftwindows_xp
*
microsoftwindows_xp
*
microsoftwindows_xp
-
microsoftinternet_explorer
5.01
microsoftwindows_2000
*
𝑥
= Vulnerable software versions