Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."
| Software | From | Fixed in |
|---|---|---|
| microsoft / internet_explorer | 7 | 7.x |
| microsoft / windows_2003_server | - | - |
| microsoft / windows_server_2003 | - | - |
| microsoft / windows_xp | - | - |
| microsoft / windows_xp | --sp2 | --sp2.x |
| microsoft / windows_server_2008 | - | - |
| microsoft / windows_server_2008 | --sp2 | --sp2.x |
| microsoft / windows_vista | - | - |
| microsoft / internet_explorer | 6 | 6.x |
| microsoft / internet_explorer | 5.01-sp4 | 5.01-sp4.x |
| microsoft / internet_explorer | 6-sp1 | 6-sp1.x |
| microsoft / windows_2000 | - | - |