Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Content-Disposition Information Disclosure Vulnerability."
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: microsoft
Published: 2011-12-14T00:00:00
Updated: 2024-08-06T23:29:56.874Z
Reserved: 2011-09-09T00:00:00
Link: CVE-2011-3404
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-12-14T00:55:01.560
Modified: 2024-11-21T01:30:27.167
Link: CVE-2011-3404
Redhat
No data.