Summary
This host is installed with Microsoft XML Core Service and is prone to information disclosure vulnerability.
Impact
Successful exploitation will allow attackers to get sensitive information from cookies and corrupt the session state.
Impact Level: System/Application
Solution
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
For updates refer to http://www.microsoft.com
Insight
Microsoft XML Core Service fails to properly restrict access from the web pages to Set-Cookie2 HTTP response headers via XMLHttpRequest calls, which are related to the HTTPOnly protection mechanism.
Affected
Microsoft, XML Core Service version 3.0/4.0/5.0/6.0 on Windows (all)
References
Severity
Classification
-
CVE CVE-2009-0419 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities