CVE-2013-1297: Microsoft Internet Explorer

Medium severity, CVSS 4.3. EPSS: 16.8% chance of exploitation in the next 30 days.

Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which allows remote attackers to perform cross-domain reading of JSON files via a crafted web site, aka "JSON Array Information Disclosure Vulnerability."

Affected products

  • Microsoft Internet Explorer: version 6 only; version 7 only; version 8 only

Published 2013-05-15. Last modified 2026-06-16.