积极预防 及时发现
快速响应 力保恢复
Internet Explorer 5.5及其之前的版本不能正确的识别在浏览器中的框架的域,这导致了...
发布时间:2001-06-27 信息来源:管理员

CNCVE编号:CNCVE-20010332 CVE编号:CAN-2001-0332 安全级别:中 漏洞中文描述: Internet Explorer 5.5及其之前的版本不能正确的识别在浏览器中的框架的域,这导致了远程网站操作者可以通过从本地框架中向在不同域中使用MSScriptControl.ScriptControl和GetObject的框架发送信息,从而阅读在客户机上的特定文件。 漏洞英文描述: Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain,which uses the frame of MSScriptControl.ScriptControl and GetObject. 漏洞参考: BUGTRAQ:20010330 Security bug in Internet Explorer - MSScriptControl.ScriptControl URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98609031517525&w=2 MS:MS01-027 URL:http://www.microsoft.com/technet/security/bulletin/MS01-027.asp 系统类型: Unix/Linux Win95/98/ME Win2000/NT Apple 漏洞类型:设计错误