>> Microsoft Internet Explorer CSS Import Information Disclosure Issue
Title : Microsoft Internet Explorer CSS Import Information Disclosure Issue VUPEN ID : VUPEN/ADV-2005-2804 CVE ID : CVE-2005-4089
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-08
Technical Description
A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to gain knowledge of sensitive information. This flaw is due to an error where the contents of certain CSS (Cascading Style Sheets) and HTML documents served from a Web site could be read by other domains via the "@import" directive and the "cssText" property, which could be exploited by remote attackers to gain unauthorized access to arbitrary documents.