Sploitus

CVE-2008-4033

2 known exploits for CVE-2008-4033

Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."

Microsoft Xml Core Services
= 4.0
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
27.7% (98th percentile)
Weakness
CWE-200
NVD status
Modified
Published
2008-11-12
CVE-2008-4033 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2008-4033

Proof-of-concept code and exploit modules indexed by Sploitus