Open Vulnerability and Assessment Language (OVAL)
Offical Language Release Repository Downloads News — November 5, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:2817 Date: 2007-01-13
Title: IE for Server 2003 Channel Definition Format Cross Domain Vulnerability
Description: Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."
Version: 3 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2005-0056
Family: windows
Platform(s): Microsoft Windows Server 2003 Product(s): Microsoft Internet Explorer
Definition Synopsis: