« Volver al listado

CVE-2008-5912

Estado: ModificadaBaja (2.1)—

Una función desconocida en la implementación JavaScript en Microsoft Internet Explorer crea y expone una "huella temporal" cuando hay un inicio de sesión actualmente a un sitio web, lo que facilita a atacantes remotos engañar a un usuario para que haga lo que le dice un mensaje pop-up envenenado, también conocido como un " ataque de phishing en una sesión activa." NOTA: a fecha de 16012009, lo único que ha salido a la luz es un pre-aviso impreciso con información no utilizable. sin embargo, ya que el investigador es conocido, se le ha asignado un identificador CVE con propósitos de seguimiento.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-5912",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-01-20T16:30:00.343",
  "references": [
    {
      "url": "http://arstechnica.com/news.ars/post/20090113-new-method-of-phishmongering-could-fool-experienced-users.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212900161",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.infoworld.com/article/09/01/13/Browser_bug_could_allow_phishing_without_email_1.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/33276",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.trusteer.com/files/In-session-phishing-advisory-2.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48173",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://arstechnica.com/news.ars/post/20090113-new-method-of-phishmongering-could-fool-experienced-users.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212900161",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.infoworld.com/article/09/01/13/Browser_bug_could_allow_phishing_without_email_1.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/33276",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.trusteer.com/files/In-session-phishing-advisory-2.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48173",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a \"temporary footprint\" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an \"in-session phishing attack.\" NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes."
    },
    {
      "lang": "es",
      "value": "Una función desconocida en la implementación JavaScript en Microsoft Internet Explorer crea y expone una \"huella temporal\" cuando hay un inicio de sesión actualmente a un sitio web, lo que facilita a atacantes remotos engañar a un usuario para que haga lo que le dice un mensaje pop-up envenenado, también conocido como un \" ataque de phishing en una sesión activa.\" NOTA: a fecha de 16012009, lo único que ha salido a la luz es un pre-aviso impreciso con información no utilizable. sin embargo, ya que el investigador es conocido, se le ha asignado un identificador CVE con propósitos de seguimiento."
    }
  ],
  "lastModified": "2026-06-16T23:01:12.810",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8682FAF3-98E3-485C-89CB-C0358C4E2AB0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}