积极预防 及时发现
快速响应 力保恢复
Internet Explorer 5.5和5.01版允许远程攻击者通过畸形的在IP地址中不包括点的...
发布时间:2001-10-30 信息来源:管理员

CNCVE编号:CNCVE-20010664 CVE编号:CAN-2001-0664 安全级别:中 漏洞中文描述: Internet Explorer 5.5和5.01版允许远程攻击者通过畸形的在IP地址中不包括点的URL绕过安全限制,这将引发Internet Explorer处理在企业内部网区内的页面,而这些页面很少有安全限制。 漏洞英文描述: Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictctions. 漏洞参考: Reference: MS:MS01-051 Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-051.asp 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误