Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
Project Subscriptions
| Vendors | Products |
|---|---|
|
Microsoft
Subscribe
|
Expression Web
Subscribe
Groove
Subscribe
Office
Subscribe
Office Compatibility Pack
Subscribe
Office Word Viewer
Subscribe
Sharepoint Server
Subscribe
Windows 2000
Subscribe
Windows 2003 Server
Subscribe
Windows 7
Subscribe
Windows Server 2008
Subscribe
Windows Vista
Subscribe
Windows Xp
Subscribe
Xml Core Services
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-08-07T10:00:42.312Z
Reserved: 2008-09-10T00:00:00
Link: CVE-2008-4033
No data.
Status : Deferred
Published: 2008-11-12T23:30:02.727
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-4033
No data.
OpenCVE Enrichment
No data.
Weaknesses