Vulnerability Details CVE-2008-5553
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.137
EPSS Ranking 93.9%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2008-5553
-
cpe:2.3:a:microsoft:internet_explorer:8