积极预防 及时发现
快速响应 力保恢复
Internet Explorer在5.5之前的版本将缓冲器里的用户用于认证安全网址的信任证书给了同...
发布时间:2000-12-19 信息来源:管理员

CNCVE编号:CNCVE-20000982 CVE编号:CVE-2000-0982 安全级别:中 漏洞中文描述: Internet Explorer在5.5之前的版本将缓冲器里的用户用于认证安全网址的信任证书给了同一网址上的不安全页面。这导致了远程攻击者通过监控网络服务器的连接而获得安全证书。 漏洞英文描述: Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credential"vulnerability. 漏洞参考: MS:MS00-076 | URL:http://www.microsoft.com/technet/security/bulletin/MS00-076.asp | BID:1793 | URL:http://www.securityfocus.com/bid/1793 | XF:ie-cache-info | URL:http://xforce.iss.net/static/5367.php 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误