"value":"Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033."
},
{
"lang":"es",
"value":"Microsoft XML Core Services, como el utilizado en Microsoft Expression Web, Office, Internet Explorer 6 y 7 y otros productos; no restringe adecuadamente el acceso de las p\u00e1ginas Web a las cabeceras de respuesta HTTP Set-Cookie2; esto permite a atacantes remotos obtener informaci\u00f3n sensible de las cookies a trav\u00e9s de llamadas XMLHttpRequest. Relacionado con el mecanismo de protecci\u00f3n HTTPOnly. NOTA: este problema existe debido a una modificaci\u00f3n inicial incompleta de CVE-2008-4033."