CVE-2008-4033
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 28%
from disclosure to weapon11 days
Published on NVDNov 12
1st PoC+11d
exploitation probability
28%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/7196⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=122703006921213&w=2https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-069http://securitytracker.com/id?1021164https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5847http://www.securityfocus.com/bid/32204http://www.us-cert.gov/cas/techalerts/TA08-316A.htmlhttp://www.vupen.com/english/advisories/2008/3111