CVE-2008-4029
Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive information from another domain via a crafted XML document, related to improper error checks for external DTDs, aka "MSXML DTD Cross-Domain Scripting Vulnerability."
- Affected products
- Xml Core Services
- Microsoft Internet Explorer
- All versions
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 26.7% (98th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2008-11-12
CVE-2008-4029 at NVD
6 known exploits for CVE-2008-4029
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft XML Core Services DTD Cross-Domain Scripting PoC MS08-069
ms08-069.txt
Microsoft XML Core Services DTD Cross-Domain Scripting PoC MS08-069
Microsoft XML Core Services DTD - Cross-Domain Scripting (MS08-069)
Microsoft XML Core Services DTD - Cross-Domain Scripting (MS08-069)
Microsoft XML Core Services DTD跨域信息泄露漏洞(MS08-069)