CVE-2011-1245 describes a JavaScript information disclosure vulnerability in Microsoft Internet Explorer 6 and 7, affecting various Windows operating systems including XP, Vista, and Server 2003/2008. This flaw allows remote attackers to obtain sensitive information by tricking users into visiting a crafted website, due to improper restrictions on script access across different domains or zones. With a CVSS score of 4.3 (medium severity), it requires medium attack complexity and results in partial confidentiality impact. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.